PaperCut Releases Second Emergency Patch for Exploited Authentication Bypass and RCE Vulnerabilities
PaperCut has released a second emergency security update for two vulnerabilities actively exploited in its PaperCut NG and MF print management software. The update addresses multiple ways attackers could bypass the original fix and compromise vulnerable servers.
The new emergency patch follows PaperCut’s initial security update for PaperCut NG and MF versions 25 and 26. The company previously warned that threat actors were exploiting a zero-day vulnerability against customer servers.
PaperCut initially withheld the vulnerabilities’ CVE identifiers and technical details while investigating the attacks and allowing customers time to install the first emergency fix.
PaperCut is now sharing technical information about two vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578. When chained together, the flaws can allow attackers to bypass authentication and potentially execute arbitrary code on affected PaperCut servers.
CVE-2026-81578 is a high-severity authentication bypass vulnerability affecting the PaperCut NG and MF web management interface. It has a CVSS score of 8.8.
“Under certain conditions, unauthenticated remote requests for administrative functions can trigger backend actions before access validation checks are complete,” PaperCut explains in its latest security advisory.
The second flaw, CVE-2026-82078, is a critical unsafe dynamic class-loading vulnerability in PaperCut’s database connection utility. The vulnerability has a CVSS score of 9.4.
The software loads database driver classes based on a configurable driver name without validating the driver against an approved allowlist.
“If an attacker can manipulate system configuration parameters, they can execute arbitrary Java bytecode present in the application classpath in the security context of the PaperCut server process,” the company says.
Cybersecurity firm watchTowr, which has been assisting PaperCut during the investigation, said the vulnerability could enable an unauthenticated attacker to bypass authentication and execute remote code on an affected PaperCut NG or MF instance in a LinkedIn post.
PaperCut emergency patch release 2
PaperCut released Emergency Patch Release 2 on Friday after additional analysis by its internal security team and external researchers from Huntress and watchTowr.
“After further work with our internal security team and external researchers such as Huntress and watchTowr, we have released an updated emergency patch, Release 2, that includes additional enhancements over the original emergency patch,” PaperCut said.
The company is urging all customers to install Emergency Patch Release 2, even if they have already applied the first emergency update.
The updated release follows watchTowr’s disclosure that its researchers had reproduced the vulnerability, identified multiple patch bypasses, and discovered additional authentication bypass issues.
BleepingComputer has contacted Huntress for additional information about its vulnerability research and will update this article if the company responds.
Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 running on Windows, Linux, and macOS. Customers using version 23 or earlier should upgrade to the latest supported version instead of waiting for patches for older releases.
PaperCut also says that site servers and secondary or print servers must be upgraded to patched versions. Other products, including Print Deploy and Mobility Print, are not affected and do not require an update.
PaperCut security recommendations
Even after applying the security update, PaperCut recommends using firewall rules, network access controls, or similar protections to restrict access to the web management interface to trusted IP addresses.
Administrators should also investigate possible post-exploitation activity involving the pc-app.exe process, missing or truncated server.log files, and the following errors in server.log:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
PaperCut has not identified the attackers or disclosed what they did after gaining access to vulnerable servers.
The company told BleepingComputer that the attacks appear to be limited and targeted. PaperCut said it would not disclose additional post-exploitation details while the investigation remains underway.
“The investigation into what the attackers are doing post-breach is still ongoing, and revealing details prematurely could complicate the response for affected customers themselves,” PaperCut said.
“What we can say: This security bulletin advises customers to be on the lookout for intrusion detection, endpoint, or network monitoring alerts associated with PaperCut application servers and will publish them as soon as we see indicators of compromise.”
PaperCut servers targeted in previous attacks
PaperCut servers were also targeted in 2023 after attackers began exploiting CVE-2023-27350, a critical authentication bypass and remote code execution vulnerability.
Those attacks were linked to multiple threat actors, including the Clop and LockBit ransomware operations, an Iranian state-sponsored hacking group, and the Bl00dy ransomware gang.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




