Security1 distinct publisher3 min readPublished
PaperCut says the advisory covers all releases of NG and MF, that exploitation is already happening in customer environments, and that its fix is an emergency patch built outside the normal release process.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The load-bearing half of this chain is the one with the lower score. CVE-2026-82078 assumes an attacker who can already set the database driver name, which by itself is configuration abuse by someone with admin reach [3]. CVE-2026-81578 supplies that precondition, letting unauthenticated remote requests trigger administrative backend actions before access validation completes [2]. Close either half and the pre-auth path shuts.
The execution primitive is narrower than the phrase remote code execution suggests. PaperCut instantiates database driver classes from a configurable name without checking it against an allowlist, so what runs is Java bytecode already present on the application classpath, in the security context of the PaperCut server process [3][5]. Horizon3 says its researchers reproduced the full pre-authentication chain against PaperCut NG [7], and PaperCut has confirmed exploitation and incidents in customer environments [6]. That is the whole of what is public on exploitation. The writeup names no actor and gives no count of affected customers [2].
Patch coverage does not match the affected set. The advisory applies to all versions of PaperCut NG and MF [8], while Emergency Patch Release 2 exists for v24, v25 and v26 only [9]. Anyone on v23 or earlier has no patch to apply and is told to upgrade to the latest supported version instead [12][1], a version migration with its own planning and testing timeline rather than a quick install. Sites that already installed the first emergency patch are asked to install Release 2 anyway, because it carries additional hardening [10]. And the build is explicitly not an official product release, having skipped PaperCut's normal release process [11]: change boards that require a signed-off GA version will have to make an exception or leave the chain open.
Two scoping details decide how far the work spreads. Site Servers and secondary or print servers also need a patched version [13]. Print Deploy and Mobility Print are not affected [14].
PaperCut's detection guidance has a built-in gap. It has published indicators for exploitation and follow-on activity, and states that absence of those indicators does not confirm a system is clean [15]. It also notes attackers may delete files and logs during exploitation [16]. Patching closes off further exploitation going forward, but it does not answer whether a given system was already compromised before the fix went in: an unpatched, internet-reachable Application Server needs to be treated as a compromise candidate rather than a remediation ticket. For anything exposed to the public internet, the vendor's interim step is to restrict web access immediately [17], which is faster to execute than any patch cycle and reversible once Release 2 is in.
One disclosure note. Horizon3 published this analysis and also sells a NodeZero Rapid Response test to validate whether the chain works in a given environment [18]. The vulnerability detail stands on PaperCut's own advisory data; the validation pitch is the vendor's.
Ranked by verification strength, evidence, and original report placement.
PaperCut has released Emergency Patch Release 2 for PaperCut NG/MF v24, v25 and v26.
PaperCut recommends installing Release 2 even if the original emergency patch was already applied, because Release 2 includes additional hardening.
PaperCut has published indicators associated with exploitation of these vulnerabilities and subsequent attacker activity, and states the absence of those indicators does not confirm that a system has not been compromised.
PaperCut notes that attackers may clean up files and logs during exploitation, so the absence of those artifacts does not rule out compromise.
Horizon3 has developed a NodeZero Rapid Response test to validate whether the PaperCut vulnerability chain can be exploited in a given environment, and recommends applying Emergency Patch Release 2 or the vendor mitigation and re-testing.
PaperCut NG and PaperCut MF are affected by two vulnerabilities that can be chained to achieve unauthenticated remote code execution on the PaperCut Application Server.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
build
An unwhitelisted JDBC driver name turns PaperCut's management port into SYSTEM1 distinct publisher
security
Attackers dump PaperCut databases through the freshly patched auth bypass chain1 distinct publisher
security
Six bugs, one order of operations: Avada's zero-click chain is a same-day patch1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed, dated, and single-origin
The technical specificity is real: two CVE identifiers, CVSS 4.0 scores of 8.8 and 9.4, CWE-306 and CWE-470 as PaperCut classified them, a named mechanism for each flaw and a plausible account of how one feeds the other. What holds the score down is provenance. Nearly all of it is PaperCut's advisory as relayed by Horizon3.ai, whose independent contribution is the statement that researchers reproduced the full pre-auth chain — a claim with no artifact, log, or third-party confirmation attached in this reporting.
Real events, no denominator
Dates we have, and they are tight: exploitation seen on August 26, vendor confirmation on the 27th, three patch drops and CVE publication on the 28th, expanded indicators on the 30th, a validation test on the 31st. Quantities we do not. Nobody here says how many environments were hit, how many are exposed, or how many have taken Release 2 — and since the advisory covers every version of NG and MF while the patch covers three lines, the population that cannot patch is unmeasured too.
Vendor numbers, vendor-adjacent framing
The alarming parts are not Horizon3's inventions — 9.4 Critical, all versions affected, exploitation confirmed all belong to PaperCut, and this writeup passes them on without embellishment. The tilt is positional rather than rhetorical: a 'Stop Guessing, Start Proving' block for the company's own NodeZero test sits between the technical detail and the patch table, and the second flaw's real precondition — configuration write access, supplied only by the first flaw — gets less prominence than its 9.4 score.
Two interested parties, no disinterested one
PaperCut is grading the severity and scope of defects in its own software, and its fix carries the unusual disclaimer that it never went through the normal release process. Horizon3.ai, the only publisher we have on this, sells the pentest platform whose new Rapid Response test is the route it offers readers for finding out whether they are exposed. Neither interest invalidates anything stated; both are worth naming, and no disinterested voice appears in our coverage to offset them.
Checkable, uncorroborated
Much of this can be verified independently by anyone with a PaperCut install — version numbers, CVE records, whether Release 2 exists for your line. The two claims that matter most cannot: that exploitation is happening in customer environments, and that every version of NG and MF is in scope. Both are PaperCut's word arriving through a single publisher, and until a second account appears the correct posture is to act on the mitigation while treating the scope statement as unconfirmed.