PaperCut Ships Second Emergency Patch As Zero-Day Chain Is Actively Exploited

PaperCut Software has released a second emergency patch after confirming that two chained vulnerabilities in PaperCut NG and PaperCut MF are being actively exploited in the wild.

PaperCut Ships Second Emergency Patch As Zero-Day Chain Is Actively Exploited

Print-management vendor PaperCut Software has issued a second emergency patch after confirming that two chained vulnerabilities — CVE-2026-82078 and CVE-2026-81578 — in its widely deployed PaperCut NG and PaperCut MF products are being actively exploited in the wild.

Chained flaws, one 9.4 critical

According to PaperCut's August 27 advisory, CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class-loading flaw in the software's database-connection utilities that allows attackers to execute arbitrary Java bytecode on the Application Server. Chained with CVE-2026-81578 — an improper access-control flaw in the web management interface — an unauthenticated remote attacker can modify system configurations and take over a server. The vendor released an initial emergency patch on August 27 and, after Huntress and watchTowr researchers identified bypasses, a second hardening patch on August 28 (Emergency Patch Release 2) that all customers are urged to install.

Multi-function office printer used with PaperCut

Confirmed incidents, uncertain reach

"We are aware of confirmed customer incidents and are treating this matter with the highest priority," PaperCut said in the advisory. Huntress reported observing base64-encoded post-exploitation commands (whoami, ver) on two victim environments, and reproduced a pre-authentication remote configuration takeover and a full RCE chain against the previous public version PaperCut NG 25.0.11.75758.

Playbook: restrict, patch, hunt

PaperCut has told organisations to immediately restrict PaperCut Application Server web interfaces to trusted internal IPs, apply Emergency Patch Release 2, and hunt for signs of compromise, including missing or truncated server.log files and telltale JDBC error strings. The vulnerability affects every version of PaperCut NG and MF prior to August 27, 2026, across Windows, Linux and macOS.

Attacks on PaperCut are a familiar playbook: in 2023, affiliates of the Clop and LockBit ransomware groups leveraged CVE-2023-27350 and CVE-2023-27351 in the same product line, and this incident lands alongside the current Manchester Airports Group breach and Hasbro employee-data leak.

Reporting based on coverage from Help Net Security (Aug. 27–28, 2026), SecurityWeek, The Hacker News and Huntress research updates.

Category: Cyber Security

Tags: Security Cybersecurity Zero-Day

Related Articles