Category: CISA Advisories
Are you still treating your office printer server as “just a printer system”?
It makes sense. You think about printers as equipment in the corner, not as a computer connected to your network, managing user accounts, storing configuration data, and communicating with other systems.
But PaperCut NG and PaperCut MF run on application servers. And on August 31, 2026, CISA added two actively exploited PaperCut vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
That means attackers are not merely testing these flaws.
They are using them.
What happened with PaperCut NG and MF?
CISA added these two vulnerabilities after PaperCut confirmed active exploitation and customer incidents:
- CVE-2026-81578: Missing Authentication for Critical Function, commonly described as an authentication bypass
- CVE-2026-82078: Unsafe Reflection, involving unsafe dynamic class loading in the database connector
The first vulnerability carries a CVSS score of 8.8 HIGH.
The second carries a CVSS score of 9.4 CRITICAL.
And here’s where it gets serious: attackers are chaining the two vulnerabilities together.
Think of your business as a building. CVE-2026-81578 can act like a faulty lock that lets someone reach administrative controls without a key. CVE-2026-82078 can then turn those controls into the ability to run unauthorized activity inside the building.
That is not a printer outage.
That can become a server compromise.
How the attack chain works
CVE-2026-81578 affects the PaperCut web management interface.
Under specific conditions, unauthenticated remote requests aimed at administrative functions can trigger backend actions before access validation is complete. In plain language, an attacker may be able to change certain system configurations without first logging in.
Here’s the problem:
Once an attacker can modify configuration, they may be able to abuse CVE-2026-82078.
This second flaw involves unsafe dynamic class loading. PaperCut NG/MF can instantiate database driver classes based on configurable driver names. The affected process does not properly validate those names against an approved allowlist.
That creates a path for arbitrary Java bytecode to execute under the security context of the PaperCut server process.
CVE-2026-82078 requires high privileges by itself. But when it is chained with the authentication bypass, an attacker may be able to reach the code-execution path without legitimate credentials.
And here's another concern: once an attacker has code execution on the PaperCut Application Server, they may attempt to install tools, steal credentials, move through the network, or prepare for ransomware.
Is your PaperCut installation affected?
PaperCut has released Emergency Patch Release 3 for NG and MF versions 24, 25, and 26.
Affected versions are those below:
- PaperCut NG/MF 24.1.9
- PaperCut NG/MF 25.0.12
- PaperCut NG/MF 26.0.4
Emergency Patch Release 3 accumulates the previous emergency releases. You do not need to install the earlier patches first.
PaperCut says Release 3 also adds additional hardening against attack chains and addresses known regressions, including:
- Broken SAML login flows
- Legacy Microsoft SQL Server driver support for external card lookup
If you applied Emergency Patch Release 1 or Release 2, you should still install Release 3.
That detail matters.
Applying an earlier emergency patch does not mean your environment is fully protected today.

What you should do immediately
1. Restrict public access
If your PaperCut Application Server is accessible from the public internet, restrict web access to trusted IP addresses immediately.
Use firewall rules, network access controls, VPN access, or equivalent controls so that the PaperCut web interface cannot be reached by untrusted internet addresses.
This is especially important if you cannot patch right away.
However, access restriction is not a replacement for patching.
A locked door is helpful. A locked door with a known weakness still needs to be repaired.
2. Apply Emergency Patch Release 3
Follow PaperCut’s official upgrade procedure and apply the correct Emergency Patch Release 3 package for your operating system and product.
Do not update only the primary Application Server and forget connected components. PaperCut recommends updating Site Servers and secondary or print servers to a patched version as well.
Your IT team should document:
- The current PaperCut product and version
- The operating system hosting each component
- Whether the system is internet-facing
- The patch release and build applied
- The date and time of verification
3. Check for signs of compromise
Because these flaws are actively exploited, do not assume that patching alone answers every question.
If a vulnerable PaperCut server was exposed to the internet, investigate it for suspicious activity before and after applying the patch.
PaperCut’s security bulletin identifies several indicators of compromise, including:
- Suspicious post-exploitation activity from
pc-app.exeorpc-app - Missing, truncated, or deleted
server.logfiles - Unexpected Java class files in the PaperCut installation directories
- Database errors containing unusual JDBC strings
- The Windows service “Remote Access Service” running
SimpleService.exe - Unexpected AnyDesk installations
- The PaperCut process launching child processes such as
cmd.exe
Relevant strings found in server.log may include:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
DB URL: jdbc:derby:memory:pwn;create=true
The absence of these indicators does not prove that your system was not compromised. Attackers may clean up files and logs as they work.
If you find evidence of compromise, isolate the server and activate your incident response procedures. PaperCut recommends securing current backups, wiping and rebuilding the Application Server, and restoring only from a clean backup created before suspicious behavior began.
Which PaperCut products are not affected?
This advisory applies to PaperCut NG and PaperCut MF.
PaperCut has stated that the following products are not affected by this issue:
- PaperCut Hive
- PaperCut Pocket
- Mobility Print
That does not mean every server in your environment is safe. It means you should identify which PaperCut products and components you actually operate before deciding what needs to be patched or investigated.
When was the last time someone reviewed that inventory?
What does the September 14 deadline mean?
CISA’s remediation deadline is September 14, 2026.
This deadline applies to U.S. federal civilian agencies under CISA’s binding requirements. Even if your organization is not a federal agency, the KEV listing is a strong warning that remediation should be prioritized now.
For a small business in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, or anywhere in Missouri, the practical takeaway is simple:
Do not wait for a convenient maintenance window if your PaperCut server is vulnerable and exposed.

How managed IT support can help
Small businesses often have a complicated technology environment without having a full-time security team. Your PaperCut server may be managed by one person who is also responsible for Microsoft 365, backups, workstations, Wi-Fi, vendors, and day-to-day support.
That is a lot to carry.
A proactive managed IT services process can help you:
- Locate every PaperCut NG/MF installation
- Confirm versions, builds, and internet exposure
- Restrict access through firewall and network rules
- Apply Emergency Patch Release 3 safely
- Review logs and endpoint alerts
- Validate backups before an incident occurs
- Coordinate rebuilding if compromise is suspected
- Strengthen ransomware protection across the business
This is also where broader cyber security solutions for small business become important. A single vulnerable server can become an entry point into file shares, user accounts, cloud services, and other systems.
Platinum Web Services provides managed IT services, network design, cybersecurity support, and 24/7 assistance for IT emergencies. We support businesses across St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and Missouri with personalized technology strategies.

The bottom line
PaperCut NG/MF is under active attack, and these two vulnerabilities can be chained from authentication bypass to arbitrary code execution.
Start by restricting public access. Then apply Emergency Patch Release 3, verify every related server, and investigate for signs of compromise.
Your printer system may look ordinary.
It is still part of your security perimeter.
If you would like help reviewing your PaperCut exposure, patching the affected systems, or improving ransomware protection, contact Platinum Web Services. We help businesses like yours stay protected with practical support available 24/7.


0 Comments