
🛡️ **CVE-2026-81578: PaperCut Zero-Day RCE Chain Exploited In-the-Wild**
Published Wednesday, September 02, 2026 at 10:49 AM PT BLUF: PaperCut NG and MF print management platforms are under active attack via a chained pair of zero-day vulnerabilities. CVE-2026-81578, a high-severity authentication bypass, combines with a second unpatched flaw to enable unauthenticated remote code execution. Immediate action required: segment PaperCut instances from untrusted networks and monitor for exploitation. DETAILS Vulnerability chain: CVE-2026-81578 (authentication bypass) chains with an unidentified second zero-day to achieve pre-authentication RCE on PaperCut NG and MF print management systems. Affected products: PaperCut NG and MF platforms; specific version range not yet disclosed in available threat intelligence. Attack vector: Remote, requires no user interaction or authentication—hostile actor can execute arbitrary code directly against exposed instances. Active exploitation confirmed: Multiple confirmed in-the-wild attacks observed; this is not theoretical or proof-of-concept. CVSS and exploit details: Severity rated high; complete CVSS and technical exploit details remain preliminary pending vendor disclosure and research publication. IMPACT ...