PaperCut releases second emergency patch for exploited flaws

Cybersecurity firm PaperCut has released a second emergency patch for two actively exploited vulnerabilities in its print management software, after researchers discovered multiple ways to bypass the initial fixes. The company had initially warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an emergency patch earlier this month.

The latest update, dubbed Emergency Patch Release 2, includes additional hardening developed with PaperCut’s internal security team and external researchers at Huntress and watchTowr. According to the company, the vulnerabilities can be chained together to bypass authentication and execute code on vulnerable servers. This means that attackers could potentially gain unauthorized access to sensitive data or take control of affected systems.

The two vulnerabilities in question are tracked as CVE-2026-82078 and CVE-2026-81578. The first, a high-severity authentication bypass vulnerability rated 8.8, impacts the PaperCut NG/MF web management interface. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to access validation checks being completed.

The second vulnerability, a critical unsafe dynamic class-loading flaw rated 9.4, exists in PaperCut’s database connection utilities. The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. This makes it possible for attackers to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process.

Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, has confirmed that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances. The company is urging all customers to install Emergency Patch Release 2 even if they already installed the first emergency patch.

The second release comes after watchTowr researchers fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass vulnerability. PaperCut has not disclosed who is behind the attacks or what threat actors are doing after compromising vulnerable servers, but says that the incidents appear limited and targeted.

For customers running version 23 or earlier of PaperCut NG/MF, the company advises upgrading to the latest version rather than waiting for a patch for those releases. Site Servers and secondary/print servers should also be upgraded to patched versions. Other components, like Print Deploy and Mobility Print, are not affected and do not require updates.

While patches are available, PaperCut is urging customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures. Administrators should also look out for suspicious post-exploitation activity from the pc-app.exe process, missing or truncated server.log files, and specific errors in the server.log.

By taking immediate action to patch and secure their systems, customers can mitigate the risk of a potential attack. It’s essential to stay vigilant and monitor system logs closely for any signs of unauthorized activity.


Source: Bleeping Computer — 2026-08-28