PaperCut has released a second emergency security patch for its NG and MF print management software after researchers found multiple ways to bypass the fixes included in its first update. The company initially warned of zero-day attacks against customer servers and issued an emergency patch for versions 25 and 26. With this new release, PaperCut is urging all customers to install the updated patch even if they already applied the first one.
The two actively exploited vulnerabilities are now tracked as CVE-2026-82078 and CVE-2026-81578, and they can be chained to bypass authentication and execute code on vulnerable servers. CVE-2026-81578 is a high-severity authentication bypass rated 8.8 that affects the PaperCut NG/MF web management interface. According to PaperCut, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks complete.
The second flaw, CVE-2026-82078, is a critical unsafe dynamic class-loading issue rated 9.4 in the software’s database connection utilities. The application loads database driver classes based on configurable driver names without checking them against an approved allowlist. If an attacker can manipulate system configuration parameters, this allows execution of arbitrary Java bytecode on the application classpath under the security context of the PaperCut server process.
Security firm watchTowr, which has been working with PaperCut during the incident, said the flaws allow unauthenticated attackers to bypass authentication and achieve remote code execution. PaperCut said Emergency Patch Release 2 includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr. watchTowr reported that its researchers fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass vulnerability.
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Customers running version 23 or earlier are advised to upgrade to the latest version instead of waiting for a patch. PaperCut says Site Servers and secondary or print servers should also be upgraded to patched versions, while components like Print Deploy and Mobility Print are not affected.
PaperCut continues to advise customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or similar measures. Administrators should look for suspicious post-exploitation activity from the pc-app.exe process, missing or truncated server.log files, and specific errors in the server log. The company has not disclosed who is behind the attacks or what threat actors do after compromising servers, describing the attacks as limited and targeted.
PaperCut said its investigation into post-compromise activity is still active, and premature disclosure could complicate affected customers’ responses. The company said it will publish indicators of compromise as they are verified. PaperCut servers were previously targeted in 2023 when attackers exploited another authentication bypass and remote code execution vulnerability.
More cybersecurity news from TechManNews.








