Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    More Details Emerge on Exploited PaperCut Vulnerabilities

    August 31, 2026

    AI Agents – Grok Bot vs Open Claw vs Poke – NextBigFuture.com

    August 31, 2026

    Xperia 10 VIII, Galaxy S26 FE are official, Poco F9 Pro and Ultra coming, Week 35 in review

    August 31, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»More Details Emerge on Exploited PaperCut Vulnerabilities
    More Details Emerge on Exploited PaperCut Vulnerabilities
    Cybersecurity

    More Details Emerge on Exploited PaperCut Vulnerabilities

    The Tech GuyBy The Tech GuyAugust 31, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation.

    Advertisement

    The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.

    The vendor issued a security bulletin on August 27 and released the first emergency patch the next day for PaperCut NG/MF versions 25 and 26. The second emergency patch was released later the same day to deliver additional hardening, including for version 24. Indicators of compromise (IoCs) have also been made available.

    It was initially believed that attackers had exploited a single vulnerability, but PaperCut and the security firms monitoring the situation, Huntress and WatchTowr, revealed that two zero-days have been exploited.

    One of them is tracked as CVE-2026-81578 and described as a high-severity authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations.

    The second flaw, CVE-2026-82078, is a critical issue related to unsafe dynamic class loading in the database connection utilities.

    Advertisement. Scroll to continue reading.

    “If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process,” PaperCut explained in its advisory.

    The company continues to update its advisory, noting on Sunday that its teams are still working on an official release that patches CVE-2026-82078 and CVE-2026-81578.

    WatchTowr reported discovering multiple patch bypasses and an additional authentication bypass flaw, which triggered the second emergency patch. 

    Huntress has seen attacks against at least two customers, with the first exploitation attempts seen on August 26.

    “Observed activity focused on system discovery,” Huntress noted. “We have not observed secondary malware, further command-and-control traffic, or additional persistence or post-exploitation from the recovered payload.”

    It’s currently unclear who is behind the attacks exploiting the PaperCut NG/MF zero-days or what their motivation is.

    Threat actors exploiting PaperCut NG/MF vulnerabilities is not unheard of. CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been exploited in ransomware attacks.

    Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation. 

    Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

    Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

    Related: Adobe and Nvidia Patch Dozens of Vulnerabilities

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    PaperCut Releases Emergency Patch for Exploited Zero-Day

    August 30, 2026

    Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

    August 29, 2026

    Hasbro Data Breach Exposed Employee Personal Information

    August 29, 2026

    Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge

    August 29, 2026

    ATF Confirms Cyber Incident After Ransomware Group Claims Attack

    August 29, 2026

    In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

    August 28, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    More Details Emerge on Exploited PaperCut Vulnerabilities

    August 31, 2026

    AI Agents – Grok Bot vs Open Claw vs Poke – NextBigFuture.com

    August 31, 2026

    Xperia 10 VIII, Galaxy S26 FE are official, Poco F9 Pro and Ultra coming, Week 35 in review

    August 31, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.