SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
PaperCut's 26.0.4 patch left its exploited pre-auth RCE chain reachable
PaperCut's 27 August 2026 advisory of in-the-wild exploitation hid a pre-auth RCE chain whose first patch, 26.0.4, watchTowr defeated within a day. Operators who patched once and stopped tracking the CVEs may still be reachable without credentials.
The Watch · Security desk

What happened
- PaperCut shipped the advisory without a patch, giving customers only indicators of compromise as log snippets and temporary mitigations to work from.
- The in-the-wild chain joined an authentication bypass, CVE-2026-81578, to a post-authentication RCE, CVE-2026-82078, giving unauthenticated code execution on the print server.
- PaperCut issued a second patch, 26.0.4-PO build 76508, which it says fixes the bypasses watchTowr reported.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The exposed set is specific: sites that installed 26.0.4, watched the three CVEs flip to fixed, and never went on to build 76508 are still reachable without credentials.
- constraint Merging bugs and their bypasses into one CVE ID means a CVE marked fixed no longer proves your build is safe, so verification has to follow build numbers, not CVE status.
- precedent watchTowr frames PaperCut's broad deployment as an attractive target for APTs and ransomware gangs, so expect this chain to be probed well past the original in-the-wild activity.
watchTowr reproduced the exploited bug from PaperCut's log-snippet IOCs against the unpatched 26.0.3, before any patch existed [7][4]. Reaching that bug without credentials came only after PaperCut shipped 26.0.4, when diffing the patch revealed the authentication bypass that completed the chain [8][9].
Then the patch gave way. watchTowr found the 26.0.4 fix for the RCE could be bypassed and reported it as WT-2026-0141 [10]. On 28 August it found the fix for the authentication bypass could be bypassed too, reported as WT-2026-0142 [11]. The two bypasses together rebuilt the full pre-auth RCE against 26.0.4, the newest build at the time [12].
The advisory and 26.0.4 both landed on 27 August; the bypass-closing build, 26.0.4-PO build 76508, landed on 28 August [2][8][1]. The first patch stood for about a day before the chain worked against it again [17].
The CVE numbering is where this gets confusing. PaperCut folded the original bugs and their patch bypasses into single CVE IDs [13]. watchTowr ended up tracking four issues, WT-2026-0141 through WT-2026-0144, against three published CVEs: CVE-2026-82077, CVE-2026-82078 and CVE-2026-81578 [14], one more issue than the CVE list shows [16].
PaperCut has been through this before. CVE-2023-27350 and CVE-2023-27351 were exploited in the wild, and the product sits in CISA's KEV catalog [6]. It runs in schools, universities, healthcare providers, government agencies and law firms [5].
What to watch
- Details on WT-2026-0143 and WT-2026-0144, the issues watchTowr's ID range implies beyond the two bypasses described.
- Confirmation of who is exploiting the chain in the wild and against which sectors.
- Whether CISA adds the 2026 PaperCut CVEs to its KEV catalog with a federal remediation deadline.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives45
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
PaperCut then released a further patch, 26.0.4-PO build 76508, containing fixes for the reported patch bypasses.
- [2]
On Thursday 27 August 2026 PaperCut published an advisory saying a vulnerability was being exploited in the wild, leading to system compromise.
- [3]
The 27 August advisory came without a patch; PaperCut provided indicators of compromise in the form of log snippets related to exploitation, plus temporary mitigations.
- [4]
The advisory concerned exploitation targeting PaperCut version 26.0.3, with no CVEs assigned at the time and only IOCs published.
- [5]
PaperCut is print management software widely used by schools, universities, healthcare providers, government agencies, law firms and businesses of all sizes.
- [6]
PaperCut has previously had vulnerabilities exploited in the wild, including CVE-2023-27350 and CVE-2023-27351, and the product is listed in CISA's Known Exploited Vulnerabilities catalog.
- [7]
Working from the in-the-wild IOCs against the unpatched version, watchTowr reproduced the post-authentication RCE later identified as CVE-2026-82078, which matched the shared indicators.
- [8]
On 27 August 2026 PaperCut released a patch, 26.0.4 for PaperCut NG.
- [9]
Diffing the 26.0.4 patch let watchTowr confirm CVE-2026-82078 (post-auth RCE) and identify and reproduce CVE-2026-81578 (authentication bypass), the full in-the-wild exploitation chain.
- [10]
watchTowr found the 26.0.4 patch for CVE-2026-82078 could be bypassed and reported it to PaperCut, tracked internally as WT-2026-0141.
- [11]
On 28 August 2026 watchTowr found the patch for CVE-2026-81578 could be bypassed too, reported to PaperCut as WT-2026-0142.
- [12]
Combining WT-2026-0141 and WT-2026-0142 gave watchTowr a full pre-auth RCE chain working against 26.0.4, the newest version at the time.
- [13]
PaperCut bundled vulnerabilities and the patch bypasses for those same vulnerabilities into singular CVE IDs, producing more watchTowr IDs than CVE IDs.
- [14]
The published CVE IDs were CVE-2026-82077, CVE-2026-82078 and CVE-2026-81578, while watchTowr tracked WT-2026-0141 through WT-2026-0144.
- [15]
watchTowr says that mix of users makes PaperCut an attractive target for APTs and ransomware gangs.
- [16]
watchTowr tracked four distinct issues against three published CVE IDs, one more tracking number than there are CVEs.
- [17]
watchTowr rebuilt the full pre-auth RCE against 26.0.4 within about a day of its release, with 26.0.4 shipping on 27 August and the working chain and build 76508 following on 28 August.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Patch bypassFollow
- Patch diffingFollow
- Print management securityFollow
- Actively Exploited Vulnerabilities and KEV MandatesFollow
Entities
- PaperCutFollow
- PaperCut NGFollow
- WatchTowrFollow
- CISA Known Exploited Vulnerabilities CatalogFollow
- CVE-2026-82078Follow
- CVE-2026-81578Follow
- CVE-2026-82077Follow
- CVE-2023-27350Follow
- CVE-2023-27351Follow