PACO.IO

Obsidian Vault Portal v2.0
guest@paco.io:~$cat "_posts/2026-09-01-ptir-daily-briefing.md"

Verification cutoff: September 1, 2026, daily edition.

Executive Summary

CISA added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities Catalog on August 31. PaperCut says every NG/MF version is affected and has published Emergency Patch Release 3 for versions 24, 25 and 26. Organizations should identify exposed installations, apply the current emergency patch, verify its integrity and inspect for compromise indicators; patching alone does not establish that a previously exploited server is clean.

Action Queue

1. Inventory and patch PaperCut NG/MF, then check for compromise

Urgency: Immediate
Importance: ★★★★★

What it is: CVE-2026-81578 is an authentication-bypass flaw that can let an unauthenticated remote attacker change certain configuration settings. CVE-2026-82078 permits unsafe dynamic class loading and can execute arbitrary Java bytecode under the PaperCut server process when chained with configuration access. PaperCut rates the latter critical. CISA added both to the KEV Catalog on August 31 after evidence of active exploitation.

Why it matters: Print-management servers can be long-lived infrastructure with directory, device and administrative connections. A successful chain crosses from unauthenticated configuration access to code execution, so the response must cover both remediation and investigation.

Recommended action: Ask the responsible IT team whether PaperCut NG/MF is deployed and whether Emergency Patch Release 3 has been applied. For systems under your authority, inventory the exact version, obtain the matching v24/v25/v26 patch from PaperCut, verify the published checksum, back up as directed and apply it. Review the vendor’s indicators before returning a suspicious host to service. Escalate and preserve evidence if the PaperCut process spawned a shell, logs are missing or truncated, suspicious JDBC/class-loading strings appear, unexpected five-character files exist under the server library path, or unapproved remote-access software is present.

Verified active: September 1, 2026; CISA’s August 31 KEV addition and PaperCut’s current urgent bulletin were checked.
Deadline: September 14, 2026, for U.S. federal civilian agencies under the KEV directive; other organizations should act immediately because exploitation is active.
Cost: The emergency security patch is available to PaperCut customers at no additional listed charge. PaperCut NG/MF itself is commercial software with deployment-dependent pricing; no universal regular price is published.
Requirements: An affected PaperCut NG/MF installation, administrative and maintenance access, an appropriate backup, the matching patch package, checksum verification and incident-response authority if indicators appear.
Official action: PaperCut urgent security bulletin and Emergency Patch Release 3 downloads · CISA Known Exploited Vulnerabilities Catalog

Linux & Self-Hosting

PaperCut provides separate emergency patch packages and checksums for Linux, Windows and macOS. Linux operators should not substitute a distribution update for the vendor’s application patch: identify the installed PaperCut branch, use the corresponding official package and validate the published hash. If investigation finds suspicious child processes, altered logging or unexpected files, preserve evidence and follow incident-response procedures before routine cleanup.

Teaching Corner

The canonical Vendor Security Bulletin Triage Lab gives beginning students a fictional inventory and sanitized indicators, then asks them to separate exposure assessment, patching and compromise investigation. It requires no scanning, exploitation or access to a real PaperCut system.

PKb Candidates

  • Emergency-patch runbook: asset owner, exposure decision, backup, official package source, checksum, installation, version verification, rollback and monitoring.
  • Patch-versus-incident decision tree: vulnerable-only systems need remediation; systems with compromise indicators also need evidence preservation, isolation, investigation and credential review.
  • Vendor-advisory extraction template: affected versions, attack prerequisites, fixed release, exploit status, deadline, indicators, mitigations and authoritative links.

CISA’s additions underscore the value of treating the KEV Catalog as a prioritization signal rather than another vulnerability feed. When a vendor bulletin supplies both a patch and investigation indicators, operational guidance should explicitly separate “no longer vulnerable” from “not previously compromised.”

Sources Consulted

PaperCut’s urgent August 27 security bulletin and vulnerability log; CISA’s August 31 alert and Known Exploited Vulnerabilities Catalog; selected technology newsletters; the latest PTIR edition; and read-only searches of the legacy recipient stream, Spam and Trash.