
PaperCut released emergency patches on August 28, 2026, to address two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078, that allow attackers to fully compromise print management servers.
The flaws enable unauthenticated attackers to modify system configurations and execute arbitrary Java bytecode, with CISA setting remediation deadlines of September 11 and September 14 for federal agencies.
Security researchers at Huntress and watchTowr confirmed that threat actors are chaining these vulnerabilities for point-and-shoot exploitation, prompting recommendations to remove servers from the public-facing internet.