PaperCut has released 'Emergency Patch Release 2' after researchers discovered that initial fixes for two critical vulnerabilities could be bypassed by attackers.
- Two critical vulnerabilities (CVE-2026-82078 and CVE-2026-81578) are being actively exploited.
- Researchers found multiple ways to bypass the initial security fixes.
- Immediate upgrade to 'Emergency Patch Release 2' is mandatory for all affected users.
The print management giant PaperCut has issued a second emergency security update for its PaperCut NG and MF software. This urgent response comes after cybersecurity researchers discovered that the initial emergency patches failed to fully protect systems from actively exploited zero-day attacks.
Deep Dive into the Vulnerabilities
The security flaws are being tracked under two specific CVE identifiers. The first, CVE-2026-81578, is an authentication bypass vulnerability with a high severity rating of 8.8. It allows unauthenticated remote requests to trigger administrative backend actions, effectively granting attackers control over the web management interface.
The second flaw, CVE-2026-82078, is even more severe, carrying a critical rating of 9.4. This is an unsafe dynamic class-loading vulnerability within the database connection utilities. If an attacker manipulates system configuration parameters, they can execute arbitrary Java bytecode under the security context of the PaperCut server process.
Cybersecurity firm watchTowr confirmed that these vulnerabilities allow unauthenticated attackers to gain full remote code execution on affected instances.
Why This Matters
BozokMedia analysis shows that print servers often serve as high-value targets in corporate environments because they frequently possess high-level network permissions. A successful compromise of a print server can lead to lateral movement across an entire organization's infrastructure, making this patch a top priority for IT administrators worldwide.
Historical Context
PaperCut has faced similar high-stakes security challenges in the past. In 2023, the company dealt with significant exploitation of CVE-2023-27350, which was linked to notorious threat actors including the Clop and LockBit ransomware operations, as well as state-sponsored hacking groups.
Frequently Asked Questions
1. Do I need to update if I already applied the first patch?
Yes. PaperCut explicitly urges all customers to install 'Release 2' even if they have already installed the first emergency patch.
2. Which versions are affected?
The vulnerabilities affect PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.