detections.ai published research on active exploitation of PaperCut NG and MF, finding two vulnerabilities CVE-2026-81578 and CVE-2026-82078 that lead to unauthenticated code execution as SYSTEM inside a print server.
Public source
Publisher name
Public post
🖨️ Two CVEs chained give you unauthenticated code execution as SYSTEM inside a print server while 47% of tracked installs cannot patch, as no patch exists... Huntress p…
Company
detections.ai
Community-Led. AI-Enhanced. Detection-Obsessed.
- Industry
- Computer and Network Security
- Company size
- 11–50 employees
About detections.ai
Building better detections, together
See moreLatest activity
Latest activity from detections.ai
5 signals
Products & Services
detections.ai noted that three samples are broken builds that construct the decoy URL and headers but never call the download, resulting in a 16-byte file containing the word error.
Products & Services
detections.ai added an array variable name $VIUSBvejbawf in all 13 LNK samples.
Products & Services
detections.ai added a YARA-L rule to catch the padded command line and 250+ leading spaces from explorer.exe to powershell.exe process.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Beazley Security
Beazley Security released a new advisory on two PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, added to CISA's KEV catalog following confirmed exploitation in the wild.
Research & Knowledge
DIAMATIX
DIAMATIX published the ThreatScope by PaperCut NG/MF led by an actively exploited attack chain affecting PaperCut NG/MF.
Research & Knowledge
watchTowr
watchTowr's team reproduced two RCE zero-days in PaperCut NG/MF, identified exposure across clients, found bypasses of the patch, and turned up another authentication bypass.
Security Corpdev
Arctic Wolf
Arctic Wolf has observed attackers actively exploiting critical PaperCut flaws CVE-2026-81578 and CVE-2026-82078 to steal SAM credentials and exfiltrate data.
Security Corporation
SecurityWeek