A critical security update has been released for PaperCut’s print management software after two vulnerabilities were found to be actively exploited by hackers. The flaws, tracked as CVE-2026-82078 and CVE-2026-81578, can bypass authentication and grant attackers remote code execution on vulnerable servers. This is the second emergency patch released in a matter of days, highlighting the urgency of addressing these issues.
PaperCut NG and MF are widely used software applications for managing print services across various industries. The vulnerabilities were initially reported to be exploited in zero-day attacks against customer servers, prompting PaperCut to release an initial emergency patch for versions 25 and 26. However, researchers discovered multiple ways to bypass the first fixes, leading to a second emergency update.
The two vulnerabilities involve authentication bypass and unsafe dynamic class-loading flaws. CVE-2026-81578 is a high-severity authentication bypass vulnerability that affects the PaperCut NG/MF web management interface. In specific conditions, unauthenticated remote requests can trigger backend actions prior to access validation checks. This allows attackers to execute malicious code on vulnerable servers.
The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut’s database connection utilities. The application loads database driver classes without validating them against an approved allowlist. Attackers can manipulate system configuration parameters to execute arbitrary Java bytecode on the server process.
Cybersecurity firm watchTowr has been working with PaperCut during the incident and reported that the vulnerabilities enable unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances. The company is urging all customers to install Emergency Patch Release 2, which includes additional hardening developed after further analysis.
The second release comes after watchTowr said its researchers fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass vulnerability. Customers running versions 24, 25, and 26 are advised to install Emergency Patch Release 2 on Windows, Linux, or macOS platforms. Those running version 23 or earlier should upgrade to the latest version rather than wait for a patch.
In addition to installing the patches, PaperCut recommends restricting access to web interfaces using firewall rules, network access controls, or equivalent measures. Administrators should also be vigilant and look out for suspicious post-exploitation activity from the pc-app.exe process, missing or truncated server.log files, and specific errors in the server.log file.
While details about the attackers and their activities are still unclear, PaperCut has assured that the attacks appear limited and targeted. The company is continuing its investigation into what attackers do after compromising vulnerable servers, but it’s essential for users to take immediate action and install the latest patches to mitigate potential risks.
Source: Bleeping Computer — 2026-08-28