2026-08-29HIGHexploitedA pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases now replace three emergency patches
PaperCut NG/MF, Scan-to-Fax path traversal to OS command execution for an authenticated administrator (CVSS 4.0 7.3), fixed in 26.0.5 and 25.0.13; part of watchTowr's pre-auth chain against the 28 August emergency build
cve · CVE-2026-82077
Coverage
1
first 2026-08-29 → last 2026-10-10
Latest activity
2026-10-10
A pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, healthcare
Sources cited
9
8 hosts
Action items (3)
Do-now tasks recorded on the entries about CVE-2026-82077, newest first. Check the date before acting on an older one.
- Upgrade every PaperCut NG/MF Application Server, Site Server and secondary/print server to the security maintenance release for its line (26.0.5, 25.0.13 or 24.1.10), starting with any still on Emergency Patch Release 1 or 2, and note that the emergency builds do not carry the fix for CVE-2026-82077, an administrator-only Scan-to-Fax code-execution flaw that the vendor's September bulletin lists as fixed in 26.0.5 and 25.0.13 and does not list for 24.1.10; for v23 and earlier, immediately restrict the Application Server's web interface to trusted/internal IP addresses only; no patch exists for that line.2026-08-29CVE-2026-81578 +2
- Before patching or restarting an internet-facing server, preserve the server/logs directory and process tree; check server.log for the two vendor-documented error strings and for an unexplained gap or truncation, check derby.log for a Derby boot line naming an in-memory database directory ending in "pwn", and hunt for a Windows service named "Remote Access Service" running SimpleService.exe (SimpleHelp) or an unexpected AnyDesk install, as PaperCut's own published incident data names both as an observed post-compromise access method.2026-08-29CVE-2026-81578 +2
- Given GreyNoise's confirmed domain-admin escalation paths, verify no PaperCut Application Server is domain-joined with a privileged service account or hosted on a domain controller, and confirm domain controllers reachable from any PaperCut host are patched against the 2021 noPac flaws (CVE-2021-42278/CVE-2021-42287); GreyNoise reports the AI-orchestrated campaign reaching full domain admin through these paths in as little as five minutes after initial access.2026-08-29CVE-2026-81578 +2
Defender insights
What each entry about CVE-2026-82077 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (11 across 9 tactics)
11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessValid Accounts: Domain Accounts · Exploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: JavaScript
- PersistenceValid Accounts: Domain Accounts · Create Account: Domain Account
- Privilege EscalationValid Accounts: Domain Accounts
- StealthIndicator Removal: File Deletion · Valid Accounts: Domain Accounts
- Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: DCSync
- DiscoveryProcess Discovery · System Information Discovery
- Lateral MovementUse Alternate Authentication Material: Pass the Hash
- Command and ControlRemote Access Tools
Initial Access TA0001
T1078.002Valid Accounts: Domain Accounts×1
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Execution TA0002
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Persistence TA0003
T1078.002Valid Accounts: Domain Accounts×1
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
T1136.002Create Account: Domain Account×1
Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and service accounts. With a sufficient level of access, the <code>net user /add /domain</code> command can be used to create a domain account.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Privilege Escalation TA0004
T1078.002Valid Accounts: Domain Accounts×1
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Stealth TA0005
T1070.004Indicator Removal: File Deletion×1
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
T1078.002Valid Accounts: Domain Accounts×1
Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Credential Access TA0006
T1003.001OS Credential Dumping: LSASS Memory×1
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
T1003.006OS Credential Dumping: DCSync×1
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Discovery TA0007
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Lateral Movement TA0008
T1550.002Use Alternate Authentication Material: Pass the Hash×1
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Command and Control TA0011
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗
Entries about PaperCut NG/MF, Scan-to-Fax path traversal to OS command execution for an authenticated administrator (CVSS 4.0 7.3), fixed in 26.0.5 and 25.0.13; part of watchTowr's pre-auth chain against the 28 August emergency build (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- PaperCut MF×1
- PaperCut NG×1
- PaperCut NG/MF, authentication bypass in the web management interface (Tapestry request-routing confusion), chained to CVE-2026-82078 for pre-auth RCE, exploited before a patch existed×1
- PaperCut NG/MF, unsafe dynamic class loading in the database connector, reached via CVE-2026-81578's config rewrite to achieve arbitrary Java bytecode execution×1
Where this entity is cited
Source distribution
- papercut.com2 (22%)
- advisories.ncsc.nl1 (11%)
- cert.ssi.gouv.fr1 (11%)
- cisa.gov1 (11%)
- greynoise.io1 (11%)
- huntress.com1 (11%)
- labs.watchtowr.com1 (11%)
- rapid7.com1 (11%)
External references
All cited sources (9)
- papercut.comprimaryPaperCut Software (vendor security bulletin)https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- papercut.comprimaryPaperCut Software (September security bulletin)https://www.papercut.com/kb/Main/security-bulletin-sep-2026/
- advisories.ncsc.nlNCSC-NL advisory NCSC-2026-0334https://advisories.ncsc.nl/advisory?id=NCSC-2026-0334
- cert.ssi.gouv.frCERT-FR (ANSSI) advisory CERTFR-2026-AVI-1095https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1095/
- cisa.govCISA KEVhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- greynoise.ioGreyNoisehttps://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf
- huntress.comHuntresshttps://www.huntress.com/blog/papercut-actively-exploited
- labs.watchtowr.comwatchTowr Labshttps://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
- rapid7.comRapid7https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild/