"Pre-authentication RCE means the attacker needs nothing from you." That blunt assessment from Seemant Sehgal, founder and CEO of BreachLock, frames the immediate danger reported after PaperCut's August 27 advisory: two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, are being exploited to gain remote access to sensitive information.
PaperCut announcement and the CVE identifiers
On August 27, PaperCut announced that hackers were exploiting a vulnerability to access sensitive information. The company shared two CVE identifiers for the flaws: CVE-2026-82078 and CVE-2026-81578. Security leaders who reviewed the advisory highlighted how the technical details map directly to high-risk outcomes inside enterprise networks.
Pre-authentication remote code execution — the practical impact (Seemant Sehgal)
Seemant Sehgal summarized the core technical threat: "Pre-authentication RCE means the attacker needs nothing from you. No credentials, no foothold, no prior access, before they own the application and can run arbitrary Java on your infrastructure." He advised that the first question for every team is whether their PaperCut instance is reachable from the internet, because external exposure "is more urgent than any patch timeline." Sehgal also noted that vulnerability scanners will enumerate the CVE but "will not tell you whether an attacker already walked through it and what the impact would be if they did."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePAPER CUT Application Server, SYSTEM privileges, and exposure on default ports (Denis Calderon)
Denis Calderon, principal and CTO at Suzu Labs, described the PaperCut Application Server as running "as SYSTEM on Windows," managing configurations "for every endpoint in the org," and offering "a web-accessible console that is often exposed to the Internet." Calderon said many exposed instances are visible on default management ports: "I ran a Shodan query this morning and found over 1,000 of these servers exposed to the public internet on their default management ports. A lot of them look like schools." He linked that exposure to PaperCut's deployment profile in education, noting that "students need to access the system from their own devices, so the web interface ends up internet-facing almost by necessity," and that the first confirmed victim to report exploitation to PaperCut was a university.
Self-erasing payloads, missing logs, and containment steps (Jacob Warner)
Jacob Warner, director of IT at Xcape, Inc, warned that the exploit chain allows an unauthenticated request to become SYSTEM on the print server and that attackers are leaving little forensic trace. "Boring infrastructure with credential-free remote code execution and self-erasing payloads is how a print server becomes a domain-wide incident," he said, adding that "because the attacker cleans up after themselves, security teams must patch now and assume the logs will not tell them if they were late to respond." Warner recommended immediate containment measures: "Defenders should patch or isolate today, close all Internet exposure, and image affected machines before remediation, as the attacker's cleanup routine may have already deleted the logs that would have confirmed exposure." He reiterated that administrators should "apply vendor patches immediately" and treat compromised print management systems as potential full-domain threats.
How Security Teams, Educational Institutions, and Incident Responders are affected
- Security teams and technologists: Must answer whether PaperCut instances are internet-facing, close external exposure, and prioritize either patching or isolation. They should treat the Application Server as a management plane running with SYSTEM privileges and assume standard logs may be incomplete if exploitation occurred.
- Educational institutions and universities: Face heightened risk because Calderon found "a lot" of internet-exposed servers that "look like schools," and the first confirmed exploitation reported to PaperCut came from a university. Institutions that allow student access to web interfaces should urgently check exposure and consider isolating instances.
- Incident responders and IT operations: Are advised to image affected machines before remediation, because "self-erasing payloads" and automated log deletion can remove forensic artifacts; traditional vulnerability scanners may not detect active zero-day exploitation.
The record laid out by these security leaders narrows to a few concrete points: the flaws are tracked as CVE-2026-82078 and CVE-2026-81578; exploitation grants SYSTEM-level control without credentials; more than 1,000 instances appear exposed on default ports; and defenders should assume forensic gaps where attackers clean up. The practical question left on the table is whether organizations with internet-facing PaperCut Application Servers will move quickly enough to isolate or patch—and whether imaging and forensic precautions will catch any intrusions already completed. For teams responsible for printers, quotas, and campus management consoles, the message from multiple experienced practitioners is simple and stark: treat the service as a trusted management plane and act now.




