Jake KnottCybersecurity and Infrastructure Security AgencyHuntresswatchTowrPaperCutPaperCut SoftwareMicrosoft

PaperCut under active zero-day attack as second emergency patch released for exploited print management flaws; researchers found multiple bypasses of initial fix

PaperCut is facing an active zero-day attack on its print management software, prompting the release of a second emergency patch for critical vulnerabilities CVE-2026-82078 and CVE-2026-81578, which have severity scores exceeding 8.8. The company advises customers to restrict server access immediately.

The Record from Recorded Future News The Record from Recorded Future News+1 source28 August 2026 · 23:34 UTC
CuriousCats Full Story

PaperCut is currently grappling with a zero-day attack on its print management software, PaperCut NG and MF, leading to the release of a second emergency patch. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores of 9.4 and 8.8 respectively, indicating critical risks.128910

The company confirmed that these vulnerabilities are actively exploited, stating, “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” as per their emergency advisory. They have urged customers to immediately restrict server access to trusted IP addresses and remove servers from public internet exposure.

The initial patch released did not adequately address the vulnerabilities, prompting collaboration with cybersecurity firms like Huntress and watchTowr to develop a more effective solution. Jake Knott, head of threat intelligence at watchTowr, emphasized the risks, noting, “PaperCut is a prime target for attackers of every motivation.” The vulnerabilities allow for authentication bypass and remote code execution, making them particularly dangerous.357

In 2023, U.S. law enforcement warned that ransomware gangs were exploiting PaperCut bugs, with the Cybersecurity and Infrastructure Security Agency (CISA) specifically advising K-12 schools about these vulnerabilities. Microsoft also reported that an Iranian state-backed group had targeted the same bugs in previous attacks.

PaperCut has made the second emergency patch available for versions 24, 25, and 26 across multiple operating systems, while advising users of earlier versions to upgrade immediately.

Key Insight
“The two vulnerabilities, rated 8.8 and 9.4, can be chained to bypass authentication and execute code. Huntress confirmed at least two customer incidents and reproduced the full pre-authentication RCE chain, while PaperCut urges restricting web access to trusted IPs.”
CuriousCats studied:
1
The Record from Recorded Future NewsThe Record from Recorded Future News
“PaperCut an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.”
The Record from Recorded Future News →
2
BleepingComputer
“PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.”
BleepingComputer →
Ask CuriousCats
What vulnerabilities are affecting PaperCut?
Who confirmed the customer incidents related to these flaws?
Why did PaperCut issue a second emergency patch?
Are other print management software vulnerable too?
How does this attack compare to previous zero-day incidents?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats