PaperCut Emergency Patch Released for Zero-Day Exploited in the Wild
PaperCut Software has issued emergency patches for a zero-day vulnerability affecting its NG and MF print management solutions that is already being exploited in the wild. The flaw, later assigned the identifiers CVE-2026-81578 and CVE-2026-82078, allows an unauthenticated attacker to gain remote control over PaperCut's trusted configuration and execute arbitrary Java code inside the application's process, according to attack data published by Huntress. PaperCut released the fixes on Friday and urged customers to install them immediately, while also recommending that administrators disconnect the application server from the public internet and restrict access to a defined list of trusted IP addresses.
The vendor confirmed that real customer incidents have been detected and is treating the situation with the highest priority. Indicators of compromise (IoCs) published by PaperCut include suspicious activity tied to pc-app.exe, the main executable of the PaperCut Application Server. The company also warned that unexpectedly truncated or deleted server.log files may indicate an active intrusion, since attackers commonly remove or modify logs to cover their tracks. Defenders running port scanner checks against their print management hosts should verify that management ports are not exposed beyond trusted networks.
This is not the first time PaperCut NG/MF has been targeted. CISA's Known Exploited Vulnerabilities (KEV) catalog already lists three prior PaperCut flaws, two of which were abused in ransomware campaigns. According to telemetry from the ShadowServer Foundation, roughly 1,000 PaperCut instances remain reachable on the public internet, with the majority concentrated in North America and Europe. With unauthenticated remote code execution now confirmed, organizations using SSL/TLS checker should also confirm that the application server is fronted by a properly hardened reverse proxy and that TLS certificates are current and valid.
Until the patch is deployed and validated, security teams should hunt for the published IoCs, audit PaperCut Application Servers for anomalous child processes spawned by pc-app.exe, and review authentication logs for unrecognised sources. Network defenders may also benefit from running a VPN/proxy detector against inbound connection attempts to identify traffic originating from anonymising infrastructure commonly used by threat actors. PaperCut said its investigation remains ongoing and additional technical guidance may follow as more details become available.