PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.
As reported earlier, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, the company had not disclosed CVE identifiers or technical details, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes.
PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities. CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface. According to PaperCut's advisory, "under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks."
The second vulnerability, CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut's database connection utilities. The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. If an attacker can manipulate system configuration parameters, this enables execution of arbitrary Java bytecode under the security context of the PaperCut server process.
Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected instances.
On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr. The company is urging all customers to install Release 2 even if they already installed the first emergency patch.