PaperCut releases second emergency patch as researchers find bypasses to initial fix

Two actively exploited vulnerabilities allow unauthenticated remote code execution on print management servers

edit
By LineZotpaper
Published
Read Time2 min
PaperCut has issued a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers at Huntress and watchTowr found ways to bypass the initial patch. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and execute arbitrary code on affected servers.

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.

As reported earlier, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, the company had not disclosed CVE identifiers or technical details, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes.

PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities. CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface. According to PaperCut's advisory, "under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks."

The second vulnerability, CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut's database connection utilities. The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. If an attacker can manipulate system configuration parameters, this enables execution of arbitrary Java bytecode under the security context of the PaperCut server process.

Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected instances.

On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr. The company is urging all customers to install Release 2 even if they already installed the first emergency patch.

§

Analysis

Why This Matters

  • Organizations using PaperCut NG/MF (widely deployed in schools, offices, and print shops) remain at risk if they have not applied the second patch.
  • The vulnerabilities are actively being exploited in the wild, meaning unpatched servers could be compromised at any time.
  • The need for a second emergency patch highlights the difficulty of fully fixing security flaws under active attack.

Background

PaperCut is a popular print management software used by businesses and educational institutions worldwide. In late August 2026, the company disclosed that two vulnerabilities were being exploited in zero-day attacks. The initial emergency patch was released quickly, but researchers soon identified bypasses, prompting a second update. Vulnerabilities in print management systems have historically been attractive targets for attackers because they often run on internal networks with elevated privileges.

Key Perspectives

PaperCut (vendor): Acting quickly to release patches and working with external researchers, but the need for a second patch suggests the initial fix was incomplete. Attackers (unknown): Exploiting the flaws in the wild, likely targeting high-value servers. The announcement of technical details may accelerate exploitation. Customers and administrators: Urged to apply the second patch immediately. Those who installed the first patch are not fully protected. Organizations face a patch-management challenge, especially if they run critical infrastructure.

What to Watch

  • Reports of widespread exploitation or ransomware campaigns leveraging these vulnerabilities.
  • Whether PaperCut releases further updates if additional bypasses are discovered.
  • The speed at which customers apply the second emergency patch across the installed base.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.