
Attackers Exploit Newly Patched PaperCut Flaws for Remote Code Execution
CybersecurityVulnerabilitiesExploitsRemoteCodeExecution
Attackers are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on vulnerable instances. The vulnerability allows unauthenticated attackers to gain remote control over PaperCut's trusted configuration, enabling arbitrary Java code execution within the application. PaperCut released an emergency fix with additional hardening to address the issue. The attack involves chaining two flaws to achieve code execution without authentication.