🚨 PaperCut NG/MF pre-auth RCE chain is being actively exploited.

https://wp.me/pfPk8e-6g4

CVE-2026-81578 (CVSS 8.8) + CVE-2026-82078 (CVSS 9.4) can be chained from unauthenticated configuration manipulation to arbitrary Java code execution. The interesting part: the initial emergency patch was bypassed, leading to Emergency Patch Release 2. My technical breakdown covers the exploit chain, Udydn.class, Derby/JDBC activity, IOCs, Sigma/YARA detection, and incident-response steps.

10 points · 2 comments · view on lemmy.world

2 Comments

solrize@lemmy.ml · 6 pts · 6d (2 replies)

From the linked post:

It is tempting to file “print management software” under boring infrastructure, and that is precisely what makes this class of product so attractive to attackers. PaperCut NG and PaperCut MF are among the most widely deployed print-management platforms in the world, dominating large enterprises, healthcare networks, and higher education — sectors where on-premise print infrastructure remains the norm and where the Application Server is routinely joined to Active Directory, holds privileged service accounts, and sits on network segments rich with lateral-movement opportunities. On Windows, the Application Server binary pc-app.exe runs as a service with SYSTEM privileges by default, so any code execution inside the Java process is, for practical purposes, full host compromise.

a_postmodern_hat@lemmy.world · 4 pts · 6d (1 reply)
[ removed ]
UnLocoPoco@lemmy.world · 1 pts · 5d

Don't forget...windows in 2026 is made by microslop so expect more of these trivial things to pop up even more here and there