PaperCut added new indicators of compromise on August 30 to its urgent warning about actively exploited PaperCut RCE flaws affecting NG and MF print-management servers. The vendor has confirmed customer incidents and says internet-accessible Application Servers require immediate action while its investigation continues.

The attacks involve two newly assigned vulnerabilities, CVE-2026-81578 and CVE-2026-82078. PaperCut released a second emergency patch for supported major versions 24, 25 and 26 on August 28 after working with Huntress and watchTowr. The vendor says Release 2 adds hardening and supersedes the first emergency patch, including for organizations that already installed the initial release.

Huntress said CVE-2026-81578 is an improper access-control flaw in the web management interface that can let an unauthenticated attacker change system configuration. It described CVE-2026-82078 as unsafe dynamic class loading in database connection utilities that can execute arbitrary Java bytecode. Chaining the flaws provides pre-authentication remote code execution on the PaperCut Application Server.

Huntress reproduced the chain against a standard PaperCut NG 25.0.11.75758 installation and found exploitation evidence in two customer environments. Its researchers observed system-discovery activity but reported no secondary malware, additional command-and-control traffic, persistence or later post-exploitation in the recovered payload. The available evidence does not identify the attackers or establish data theft.

PaperCut advises defenders to examine activity spawned by the legitimate pc-app.exe process and to investigate server.log files that are missing, deleted or altered. Its updated advisory lists database errors involving jdbc:no:x or cardID lookups among potential indicators, while warning that their absence does not prove a server is clean. Administrators should preserve logs and conduct incident-response review where exposure existed.

Organizations should install Emergency Patch Release 2 and restrict PaperCut web interfaces to trusted IP addresses through firewall or network-access rules. PaperCut recommends that publicly exposed servers be isolated from untrusted internet access even when no suspicious activity has been seen, and says customers should continue monitoring its advisory for verified remediation and investigation updates.