Security

PaperCut Exploit Chain Achieves Full RCE via Automated Pipeline

Two vulnerabilities combined with in-memory persistence techniques create a weaponized attack system targeting thousands of legacy installations.

Omega Editorial· September 12, 2026· 3 min read

Two-Stage Attack Bypasses Authentication, Loads Malicious Code

Security researchers at Huntress detected suspicious activity on August 26 involving base64-encoded reconnaissance commands targeting PaperCut NG and MF print management software. The activity represented exploitation of a vulnerability chain now tracked as CVE-2026-81578 and CVE-2026-82078, according to details first reported by Forkast News.

The attack sequence begins with CVE-2026-81578, an authentication bypass vulnerability rated 8.8 on the CVSS scale. This flaw allows attackers to circumvent login requirements entirely. Once past authentication controls, attackers modify the database connector configuration to prepare for the second stage.

CVE-2026-82078, the more severe vulnerability with a CVSS score of 9.4, involves unsafe dynamic class loading. Attackers inject a crafted JDBC URL that forces the PaperCut Application Server to load attacker-controlled Java classes. The result is pre-authentication remote code execution without valid credentials.

Automated Exploitation Shows Iterative Refinement

Data from watchTowr honeypots reveals this is not manual exploitation. The attack follows a fully automated pipeline: mass scanning and fingerprinting, authentication bypass, configuration modification, JDBC URL injection, and delivery of hex-encoded Java class payloads.

Researchers observed evidence of iterative development within the attack infrastructure. In one documented case, an attacker attempted exploitation, failed to deploy the implant, debugged the payload, and returned approximately one hour later with a successful attack. This pattern indicates automated systems capable of self-correction and refinement at scale.

In-Memory Persistence Evades Traditional Detection

Post-compromise activity focuses on maintaining access while avoiding file-based detection mechanisms. Attackers deploy the Godzilla C2 webshell and suo5 proxy tunnel as Jetty servlet filters that reside entirely in memory. This approach bypasses standard disk-scanning security tools.

For more durable access, attackers install legitimate remote management tools including SimpleHelp and AnyDesk, configured to run as LocalSystem with automatic startup. Additional actions include dumping Windows registry hives to extract the SAM database BootKey and harvesting credentials for lateral movement across networks.

Nearly Half of Installations Cannot Be Patched

PaperCut has released fixes in versions 26.0.5, 25.0.13, and 24.1.10. However, no patches exist for version 23 or earlier. Huntress data shows that 47% of approximately 2,500 tracked PaperCut installations run these unpatchable legacy versions.

The patching situation is further complicated by the fact that initial emergency patches were bypassable via the Home page display, requiring subsequent hardening releases. Education institutions including K-12 schools and universities, along with government and healthcare organizations, represent the primary targets.

Why it matters

This incident demonstrates how attackers are industrializing vulnerability exploitation through automated pipelines that can debug and refine attacks in real time. The combination of legacy software constraints and in-memory persistence techniques creates a security gap that traditional detection methods cannot address. Organizations running print management infrastructure face a choice between operational disruption from upgrades or continued exposure to automated exploitation at scale.

These details were first reported by Forkast News as a follow-up to previous coverage of PaperCut authentication vulnerabilities.

#papercut#remote code execution#vulnerability exploitation#automated attacks#in-memory malware#legacy software

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 4 min read

AI Tools Now Generate 685% More Security Alerts—But 94% Are Noise

Enterprise SOCs face a new triage challenge as coding agents and employee AI use trigger alarms that look like intrusions but almost never are.

Via AI Watch · Sep 12, 2026
Security· 3 min read

Anthropic Reports Claude AI Exploited for State Hacking, Bioweapons

New disclosure reveals Russian state actors, cybercriminals, and would-be bioweapon developers all abused the AI assistant over eight months.

Via WIRED · Sep 12, 2026
Security· 3 min read

Okta Pitches Identity Tools to Manage Surging AI Agent Deployments

The identity platform provider is betting enterprises will use existing access controls to govern autonomous software, not build separate systems.

Via AI Watch · Sep 12, 2026