viz.greynoise.io Active Exploitation of PaperCut Vulnerabilities CVE-2026-81578 and CVE-2026-82078
Article Content
- •CVE-2026-81578 allows unauthorized admin actions via an access control bypass.
- •CVE-2026-82078 enables arbitrary code execution through unsafe dynamic class loading.
- •Both vulnerabilities are actively exploited, with CISA listing them on August 31, 2026.
Two critical vulnerabilities in PaperCut MF/NG have been identified, CVE-2026-81578 and CVE-2026-82078, both published on August 28, 2026. CVE-2026-81578 allows unauthenticated attackers to exploit an access control bypass via crafted POST requests, enabling administrative actions. CVE-2026-82078 involves unsafe dynamic class loading, which can lead to arbitrary Java bytecode execution on the server. Both vulnerabilities were added to the CISA KEV list on August 31, 2026, indicating active exploitation in the wild. Attackers are targeting the Tapestry web interface of PaperCut systems, affecting organizations relying on these applications. The current status of these vulnerabilities is critical, with ongoing exploitation reported. Security professionals are urged to take immediate action to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-81578 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Chrome Zero-Day CVE-2026-85046 Exploited in the Wild Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity zero-day vulnerability in the V8 JavaScript and WebAssembly engine, rated 8.8 on the CVSS scale. The flaw, identified as a type confusion issue, allows remote attackers to execute arbitrary code within Chrome's sandbox by…
AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally A Russian-speaking threat actor has exploited vulnerabilities CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF software, compromising at least 440 instances across 395 organizations in 48 countries. The campaign began on August 31, 2026, utilizing hundreds of AI agents powered by OpenAI's Codex and DeepSeek models…