PaperCut Exploit Chain Achieves Full RCE via Automated Pipeline
Two vulnerabilities combined with in-memory persistence techniques create a weaponized attack system targeting thousands of legacy installations.

Two-Stage Attack Bypasses Authentication, Loads Malicious Code
Security researchers at Huntress detected suspicious activity on August 26 involving base64-encoded reconnaissance commands targeting PaperCut NG and MF print management software. The activity represented exploitation of a vulnerability chain now tracked as CVE-2026-81578 and CVE-2026-82078, according to details first reported by Forkast News.
The attack sequence begins with CVE-2026-81578, an authentication bypass vulnerability rated 8.8 on the CVSS scale. This flaw allows attackers to circumvent login requirements entirely. Once past authentication controls, attackers modify the database connector configuration to prepare for the second stage.
CVE-2026-82078, the more severe vulnerability with a CVSS score of 9.4, involves unsafe dynamic class loading. Attackers inject a crafted JDBC URL that forces the PaperCut Application Server to load attacker-controlled Java classes. The result is pre-authentication remote code execution without valid credentials.
Automated Exploitation Shows Iterative Refinement
Data from watchTowr honeypots reveals this is not manual exploitation. The attack follows a fully automated pipeline: mass scanning and fingerprinting, authentication bypass, configuration modification, JDBC URL injection, and delivery of hex-encoded Java class payloads.
Researchers observed evidence of iterative development within the attack infrastructure. In one documented case, an attacker attempted exploitation, failed to deploy the implant, debugged the payload, and returned approximately one hour later with a successful attack. This pattern indicates automated systems capable of self-correction and refinement at scale.
In-Memory Persistence Evades Traditional Detection
Post-compromise activity focuses on maintaining access while avoiding file-based detection mechanisms. Attackers deploy the Godzilla C2 webshell and suo5 proxy tunnel as Jetty servlet filters that reside entirely in memory. This approach bypasses standard disk-scanning security tools.
For more durable access, attackers install legitimate remote management tools including SimpleHelp and AnyDesk, configured to run as LocalSystem with automatic startup. Additional actions include dumping Windows registry hives to extract the SAM database BootKey and harvesting credentials for lateral movement across networks.
Nearly Half of Installations Cannot Be Patched
PaperCut has released fixes in versions 26.0.5, 25.0.13, and 24.1.10. However, no patches exist for version 23 or earlier. Huntress data shows that 47% of approximately 2,500 tracked PaperCut installations run these unpatchable legacy versions.
The patching situation is further complicated by the fact that initial emergency patches were bypassable via the Home page display, requiring subsequent hardening releases. Education institutions including K-12 schools and universities, along with government and healthcare organizations, represent the primary targets.
Why it matters
This incident demonstrates how attackers are industrializing vulnerability exploitation through automated pipelines that can debug and refine attacks in real time. The combination of legacy software constraints and in-memory persistence techniques creates a security gap that traditional detection methods cannot address. Organizations running print management infrastructure face a choice between operational disruption from upgrades or continued exposure to automated exploitation at scale.
These details were first reported by Forkast News as a follow-up to previous coverage of PaperCut authentication vulnerabilities.
This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.
Want systems like this working for your business?
Book a Call
