PaperCut Software has released a second emergency patch to address zero-day vulnerabilities exploited against its print management solutions, affecting thousands of users worldwide.
A group of attackers has been targeting PaperCut NG and MF instances, bypassing authentication and achieving remote code execution on affected systems. Initially, it was thought that only one vulnerability had been exploited, but further investigation revealed two separate flaws, tracked as CVE-2026-81578 and CVE-2026-82078. The first is a high-severity authentication bypass that allows an attacker to modify system configurations, while the second is a critical issue related to unsafe dynamic class loading in database connection utilities.
The exploitation of these vulnerabilities has been observed in multiple instances, with at least two customers affected by Huntress, a cybersecurity firm monitoring the situation. The company’s security teams have reported observing “system discovery” activity without any secondary malware or further command-and-control traffic. It remains unclear who is behind the attacks and what their motivation may be.
PaperCut has taken swift action to address the vulnerabilities, releasing an initial emergency patch on August 28 for versions 25 and 26, followed by a second patch later that day to include additional hardening for version 24. Indicators of compromise (IoCs) have also been made available to affected users.
The exploitation of PaperCut NG/MF vulnerabilities is not new; CISA’s Known Exploited Vulnerabilities catalog includes three other flaws, two of which have been exploited in ransomware attacks. Furthermore, roughly 1,000 PaperCut instances are currently exposed to the internet, primarily located in North America and Europe, according to data from the ShadowServer Foundation.
The severity of this situation highlights the importance of regular security updates and patches for critical software components like print management solutions. As attackers continually seek out vulnerabilities to exploit, it’s essential for organizations to remain vigilant and address any potential threats promptly. In light of this incident, we recommend that users review their PaperCut configurations, ensure they have applied the latest patches, and monitor their systems closely for any signs of malicious activity.
It’s also worth noting that PaperCut is just one example of a software vendor responding to emerging threats; other companies, such as Adobe and Nvidia, have recently released patches addressing dozens of vulnerabilities. In today’s threat landscape, staying informed and up-to-date on the latest security developments is crucial for protecting against increasingly sophisticated attacks.
Source: SecurityWeek — 2026-08-31