Start your day with intelligence. Get The OODA Daily Pulse.
PaperCut issues second emergency patch as two zero‑days see active exploitation.
PaperCut released a second emergency patch after investigators confirmed attackers are exploiting two zero‑day flaws that allow unauthenticated access, configuration tampering and remote code execution on NG and MF servers. The company said CVE‑2026‑81578 enables authentication bypass while CVE‑2026‑82078 stems from unsafe dynamic class loading, with patch bypasses and an additional flaw prompting rapid hardening across versions 24 through 26. Huntress and WatchTowr have observed early attacks focused on system discovery, and PaperCut continues updating its advisory while working on full fixes. Roughly 1,000 internet‑exposed instances remain at risk, and past PaperCut vulnerabilities have been linked to ransomware groups, though the actors behind the current exploitation are still unknown.
Read more:
https://www.securityweek.com/more-details-emerge-on-exploited-papercut-vulnerabilities/