PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes. PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface. "Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks," explains PaperCut's updated advisory. The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut's database connection utilities. The application loads database driver classes based ...
PaperCut releases second emergency patch for exploited flaws
Affected Software
Frequently Asked Questions
Which PaperCut products and components are affected?
The vulnerabilities affect PaperCut NG and MF print management software, including the web management interface and database connection utilities. The initial emergency patch targeted versions 25 and 26.
What can attackers do by chaining the two vulnerabilities?
The flaws can be chained to bypass authentication and execute code on vulnerable servers. CVE-2026-81578 specifically allows unauthenticated remote requests targeting administrative functions to trigger backend actions under specific conditions.
Why did PaperCut release a second emergency update?
Researchers found multiple ways to bypass the initial fixes. PaperCut released the second emergency security update while the vulnerabilities were being actively exploited in zero-day attacks against customer servers.
What is confirmed about the vulnerabilities?
PaperCut has assigned CVE-2026-82078 and CVE-2026-81578 to the two issues and disclosed that they are actively exploited. CVE-2026-81578 is rated high severity with a CVSS score of 8.8.