CVE Tools

More Details Emerge on Exploited PaperCut Vulnerabilities

SecurityWeekBy Eduard Kovacs

Reported exploitedPaperCut NGPaperCut MF

Our summary

PaperCut Software has issued a second emergency patch to address two zero-day vulnerabilities being actively exploited against PaperCut NG and MF versions 24, 25, and 26. The flaws enable unauthenticated attackers to bypass authentication and execute remote code via CVE-2026-81578, a high-severity configuration manipulation bug, and CVE-2026-82078, a critical issue involving unsafe dynamic class loading. This rapid follow-up response was necessitated by the discovery of patch bypasses by security researchers, prompting immediate hardening measures alongside the initial fix. While the threat actor behind the ongoing in-the-wild attacks remains unidentified, defenders should apply the latest updates immediately to mitigate the risk.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store