Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

PaperCut's 26.0.4 patch left its exploited pre-auth RCE chain reachable

PaperCut's 27 August 2026 advisory of in-the-wild exploitation hid a pre-auth RCE chain whose first patch, 26.0.4, watchTowr defeated within a day. Operators who patched once and stopped tracking the CVEs may still be reachable without credentials.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying PaperCut's 26.0.4 patch left its exploited pre-auth RCE chain reachable
Generated illustration

What happened

  • PaperCut shipped the advisory without a patch, giving customers only indicators of compromise as log snippets and temporary mitigations to work from.
  • The in-the-wild chain joined an authentication bypass, CVE-2026-81578, to a post-authentication RCE, CVE-2026-82078, giving unauthenticated code execution on the print server.
  • PaperCut issued a second patch, 26.0.4-PO build 76508, which it says fixes the bypasses watchTowr reported.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The exposed set is specific: sites that installed 26.0.4, watched the three CVEs flip to fixed, and never went on to build 76508 are still reachable without credentials.
  • constraint Merging bugs and their bypasses into one CVE ID means a CVE marked fixed no longer proves your build is safe, so verification has to follow build numbers, not CVE status.
  • precedent watchTowr frames PaperCut's broad deployment as an attractive target for APTs and ransomware gangs, so expect this chain to be probed well past the original in-the-wild activity.

watchTowr reproduced the exploited bug from PaperCut's log-snippet IOCs against the unpatched 26.0.3, before any patch existed [7][4]. Reaching that bug without credentials came only after PaperCut shipped 26.0.4, when diffing the patch revealed the authentication bypass that completed the chain [8][9].

Then the patch gave way. watchTowr found the 26.0.4 fix for the RCE could be bypassed and reported it as WT-2026-0141 [10]. On 28 August it found the fix for the authentication bypass could be bypassed too, reported as WT-2026-0142 [11]. The two bypasses together rebuilt the full pre-auth RCE against 26.0.4, the newest build at the time [12].

The advisory and 26.0.4 both landed on 27 August; the bypass-closing build, 26.0.4-PO build 76508, landed on 28 August [2][8][1]. The first patch stood for about a day before the chain worked against it again [17].

The CVE numbering is where this gets confusing. PaperCut folded the original bugs and their patch bypasses into single CVE IDs [13]. watchTowr ended up tracking four issues, WT-2026-0141 through WT-2026-0144, against three published CVEs: CVE-2026-82077, CVE-2026-82078 and CVE-2026-81578 [14], one more issue than the CVE list shows [16].

PaperCut has been through this before. CVE-2023-27350 and CVE-2023-27351 were exploited in the wild, and the product sits in CISA's KEV catalog [6]. It runs in schools, universities, healthcare providers, government agencies and law firms [5].

What to watch

  • Details on WT-2026-0143 and WT-2026-0144, the issues watchTowr's ID range implies beyond the two bypasses described.
  • Confirmation of who is exploiting the chain in the wild and against which sectors.
  • Whether CISA adds the 2026 PaperCut CVEs to its KEV catalog with a federal remediation deadline.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+8
Incentives45
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    PaperCut then released a further patch, 26.0.4-PO build 76508, containing fixes for the reported patch bypasses.

  2. [2]

    On Thursday 27 August 2026 PaperCut published an advisory saying a vulnerability was being exploited in the wild, leading to system compromise.

    ReportedSupportedView cited source
  3. [3]

    The 27 August advisory came without a patch; PaperCut provided indicators of compromise in the form of log snippets related to exploitation, plus temporary mitigations.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. labs.watchtowr.com

    1 article · October 9, 2026

    Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories