PaperCut issues second emergency patch after zero-day attacks
PaperCut released a second emergency patch after attackers exploited two NG/MF zero-days that enable unauthenticated remote code execution on affected servers.
PaperCut released a second emergency update after attackers exploited two zero-day vulnerabilities in its NG and MF print management software. The vendor published a security bulletin on August 27 and issued an initial emergency fix on August 28 for versions 25 and 26; a second emergency patch was released later the same day to add further hardening and to cover version 24. Indicators of compromise were published alongside the advisories.
Security teams tracking the incident confirmed the attacks used two distinct zero-days rather than a single flaw. One is tracked as CVE-2026-81578, described as a high-severity authentication bypass that allows an unauthenticated attacker to change certain system configuration parameters. The other, CVE-2026-82078, is a critical vulnerability related to unsafe dynamic class loading in the database connection utilities. PaperCut warned that if an attacker can manipulate configuration parameters, they may execute arbitrary Java bytecode on the application classpath under the PaperCut server process.
A security firm identified multiple ways to bypass the initial emergency patch and found an additional authentication bypass, prompting the follow-up release. Another company monitoring the activity reported attacks against at least two customers, with the first observed exploitation attempts on August 26. Observed activity concentrated on system discovery; investigators have not found secondary malware, command-and-control traffic, or further persistence tied to recovered payloads so far.
The U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog lists three other PaperCut flaws, two of which have been used in ransomware campaigns. Internet exposure data from the ShadowServer Foundation shows roughly 1,000 PaperCut servers reachable from the public internet, most located in North America and Europe.
PaperCut is updating its advisory while development teams work on a full patch for CVE-2026-82078 and CVE-2026-81578. The vendor advises customers to apply the emergency updates immediately and to review the provided indicators of compromise. Security firms advising affected organizations recommend applying the patches, restricting network access to management interfaces, and monitoring for unexpected configuration changes or unusual Java activity.








