CVE Tools

PaperCut releases second emergency patch for exploited flaws

BleepingComputerBy Lawrence Abrams

Reported exploitedPaperCut

Our summary

PaperCut has issued Emergency Patch Release 2 for its NG and MF print management platforms, addressing two vulnerabilities currently being exploited in the wild: CVE-2026-81578 and CVE-2026-82078. This urgent update follows discovery of multiple bypass techniques against the initial fix, allowing unauthenticated attackers to chain these flaws for full remote code execution. The advisory covers versions 24, 25, and 26 across Windows, Linux, and macOS, with older releases requiring a full upgrade.

CVE-2026-81578 is a high-severity authentication bypass (CVSS 8.8) in the web management interface, while CVE-2026-82078 is a critical flaw (CVSS 9.4) involving unsafe dynamic class loading in database utilities. Researchers at watchTowr and Huntress helped identify the initial attack vectors and subsequent bypasses. Administrators are strongly urged to install the new patch immediately, restrict web interface access via firewall rules, and monitor server logs for specific error strings indicating post-exploitation activity.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store