Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Organizations using PaperCut NG and MF
Incident: Exploitation of chained vulnerabilities CVE-2026-82078 and CVE-2026-81578 for remote code execution.
Impact: Full system compromise allowing attackers to execute arbitrary code and potentially exfiltrate sensitive print data.
Attacker: Unidentified threat actors
Analysis: Threat actors are exploiting a combination of improper access control and unsafe dynamic class loading to bypass authentication. This chain allows the execution of arbitrary Java code within the application process. Early evidence shows attackers using encoded commands to fingerprint targeted systems for further pivoting.
Recommendations: Immediately apply the latest emergency hardening patches from PaperCut.; Restrict public internet access to PaperCut management interfaces.; Audit server logs for ‘Database error looking up cardID: VALUES CAST’ indicators.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source