PaperCut Issues Second Emergency Patch After Initial Fixes Bypassed
A critical chain of vulnerabilities in NG and MF print management software allows unauthenticated remote code execution.
PaperCut has released Emergency Patch Release 2 for its NG and MF print management software after researchers discovered bypasses for an initial fix. The update addresses two actively exploited vulnerabilities that allow unauthenticated attackers to seize control of affected servers.
The company issued the second emergency release to address a critical vulnerability chain. The first flaw, CVE-2026-81578, is a high-severity authentication bypass with a CVSS score of 8.8 affecting the web management interface. This can be paired with CVE-2026-82078, a critical unsafe dynamic class-loading flaw in database connection utilities with a CVSS score of 9.4. This second flaw allows for the execution of arbitrary Java bytecode. When chained, these vulnerabilities enable unauthenticated remote attackers to achieve remote code execution (RCE) on the target system.
A History of Targeting
This security crisis follows a pattern of interest in PaperCut infrastructure by sophisticated threat actors. In 2023, the company dealt with the exploitation of CVE-2023-27350, which was leveraged by a variety of groups including the Bl00dy Ransomware Gang, LockBit, Clop, and Iranian state-backed actors. To resolve the current flaws, PaperCut collaborated with security firms Huntress and watchTowr. In a statement, PaperCut noted that the second release includes "additional hardening beyond the original emergency patch" following work with these external researchers and their internal security team.
Infrastructure Risks
The severity of these flaws stems from the role print management servers play within corporate and educational networks. These servers typically operate with high-level system privileges and serve as critical infrastructure. Because the vulnerabilities are accessible via a web interface without requiring authentication, they provide a direct vector for attackers to deploy ransomware or exfiltrate sensitive data. The ability to execute arbitrary code at a system level makes these servers high-value targets for initial entry into a protected network.
Immediate Action Required
PaperCut is urging all customers using versions 24, 25, and 26 to apply the second patch immediately. Emergency Patch Release 2 is currently available for these versions across Windows, Linux, and macOS platforms. Administrators are advised to verify their version numbers and deploy the update to prevent exploitation of the authentication bypass and subsequent RCE chain.