#2
The Hacker News
general
August 28, 2026 at 17:12 UTC
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
By [email protected] (The Hacker News)
AI Summary
Attackers are chaining two vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution, prompting PaperCut to issue an emergency patch with additional hardening measures. The exploit gives unauthenticated attackers remote control over PaperCut's trusted configuration layer, enabling arbitrary Java code execution inside the application server. Security practitioners running PaperCut in enterprise print environments should apply the emergency patch immediately.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →