• News/
  • bleepingcomputer-20260828190826

PaperCut releases second emergency patch for exploited flaws

BleepingComputer
·
Lawrence Abrams
·
Published Aug 28, 2026
·
Updated

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26. At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes. PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface. "Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks," explains PaperCut's updated advisory. The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut's database connection utilities. The application loads database driver classes based ...

Read full article

Affected Software

3 affected components
PaperCut PaperCut NG/MF print management software=25, =26, >=24<=26
PaperCut PaperCut NG/MF web management interface=25, =26
PaperCut PaperCut NG/MF database connection utilities=25, =26

Frequently Asked Questions

1

Which PaperCut products and components are affected?

The vulnerabilities affect PaperCut NG and MF print management software, including the web management interface and database connection utilities. The initial emergency patch targeted versions 25 and 26.

2

What can attackers do by chaining the two vulnerabilities?

The flaws can be chained to bypass authentication and execute code on vulnerable servers. CVE-2026-81578 specifically allows unauthenticated remote requests targeting administrative functions to trigger backend actions under specific conditions.

3

Why did PaperCut release a second emergency update?

Researchers found multiple ways to bypass the initial fixes. PaperCut released the second emergency security update while the vulnerabilities were being actively exploited in zero-day attacks against customer servers.

4

What is confirmed about the vulnerabilities?

PaperCut has assigned CVE-2026-82078 and CVE-2026-81578 to the two issues and disclosed that they are actively exploited. CVE-2026-81578 is rated high severity with a CVSS score of 8.8.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203