- PaperCut issued an emergency advisory on Thursday evening regarding the active exploitation of vulnerabilities in their print management software, PaperCut NG and MF.
- The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, both carry severity scores over 8.8 out of 10.
- An initial patch released by PaperCut was found to be insufficient, as researchers discovered multiple bypasses.
- On Friday, PaperCut released Emergency Patch Release 2, which includes additional hardening developed after further analysis.
- Huntress reported at least two customer incidents and successfully reproduced the full pre-authentication RCE chain.
- PaperCut is urging all customers to install Release 2 and restrict web access to trusted IPs.
- The vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances.
- CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface.
- The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4.
- PaperCut has not disclosed who is behind the attacks or the actions of the threat actors post-compromise.
PaperCut is currently grappling with a zero-day attack on its print management software, PaperCut NG and MF, leading to the release of a second emergency patch. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores of 9.4 and 8.8 respectively, indicating critical risks.128910
The company confirmed that these vulnerabilities are actively exploited, stating, “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” as per their emergency advisory. They have urged customers to immediately restrict server access to trusted IP addresses and remove servers from public internet exposure.
The initial patch released did not adequately address the vulnerabilities, prompting collaboration with cybersecurity firms like Huntress and watchTowr to develop a more effective solution. Jake Knott, head of threat intelligence at watchTowr, emphasized the risks, noting, “PaperCut is a prime target for attackers of every motivation.” The vulnerabilities allow for authentication bypass and remote code execution, making them particularly dangerous.357

In 2023, U.S. law enforcement warned that ransomware gangs were exploiting PaperCut bugs, with the Cybersecurity and Infrastructure Security Agency (CISA) specifically advising K-12 schools about these vulnerabilities. Microsoft also reported that an Iranian state-backed group had targeted the same bugs in previous attacks.
PaperCut has made the second emergency patch available for versions 24, 25, and 26 across multiple operating systems, while advising users of earlier versions to upgrade immediately.
“The two vulnerabilities, rated 8.8 and 9.4, can be chained to bypass authentication and execute code. Huntress confirmed at least two customer incidents and reproduced the full pre-authentication RCE chain, while PaperCut urges restricting web access to trusted IPs.”







