PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE | Huntress

August 29, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: huntress.com

Threat Risk: High
Victim: Organizations using PaperCut NG or MF print management software
Incident: Active exploitation of a pre-authentication RCE vulnerability chain in PaperCut software.
Impact: Complete remote takeover of the PaperCut Application Server, allowing arbitrary code execution.
Attacker: Unidentified threat actors
Analysis: Attackers are chaining an improper access control flaw with an unsafe dynamic class-loading vulnerability to achieve pre-authentication remote code execution. Huntress has observed active exploitation involving base64-encoded reconnaissance commands executed on targeted servers. This chain allows an attacker to completely compromise the Application Server process without any prior credentials.
Recommendations: Immediately apply emergency patches for PaperCut NG/MF versions 25 and 26.; Remove all public-facing exposure of the PaperCut web management interface.; Monitor for suspicious Java processes spawning command shells or unexpected .class files in server directories.
Source: Huntress

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *