The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory
On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This activity signaled the exploitation of PaperCut NG and MF, specifically targeting a chain of vulnerabilities that would soon be formally assigned as CVE-2026-81578 and CVE-2026-82078. The Mechanics of the Chain The attack relies on…