PaperCut flaws enable pre-auth RCE, active exploitation reported
A chain of PaperCut vulnerabilities (WT-2026-0141-0144 / CVE-2026-82077, CVE-2026-82078, CVE-2026-81578) allows pre-authentication remote code execution. Exploitation is already active and some vendor patches can be bypassed due to architectural weaknesses.
- CVE-2026-82077: insufficient input validation in print jobs
- CVE-2026-82078: buffer overflow in the print spooler service
- CVE-2026-81578: privilege escalation to system level
- Exploits run pre-auth and bypass issued patches
Read next
Security