Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Executive Summary

Malicious actors exploit a newly patched flaw in PaperCut NG and MF, chaining two vulnerabilities to gain remote code execution without authentication. The attack leverages the application's trusted configuration, allowing arbitrary Java code execution. PaperCut released an emergency fix with additional hardening to mitigate the threat.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-28T17:12:15+00:00 - Category: threat-intel

Original Description: Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

"We must become the change we want to see."

— Mahatma Gandhi
Source: The Hacker News