PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
Reported exploitedPaperCut NG/MFOur summary
PaperCut has published new regular maintenance releases for PaperCut NG/MF, specifically versions 26.0.5, 25.0.13, and 24.1.10, to supersede previous emergency patch builds. These fully tested updates resolve two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which are currently being exploited in the wild to bypass authentication and execute arbitrary code. Administrators should migrate to these standard releases immediately to ensure comprehensive security coverage and stability.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.