PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation.
The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.
The vendor issued a security bulletin on August 27 and released the first emergency patch the next day for PaperCut NG/MF versions 25 and 26. The second emergency patch was released later the same day to deliver additional hardening, including for version 24. Indicators of compromise (IoCs) have also been made available.
It was initially believed that attackers had exploited a single vulnerability, but PaperCut and the security firms monitoring the situation, Huntress and WatchTowr, revealed that two zero-days have been exploited.
One of them is tracked as CVE-2026-81578 and described as a high-severity authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations.
The second flaw, CVE-2026-82078, is a critical issue related to unsafe dynamic class loading in the database connection utilities.
“If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process,” PaperCut explained in its advisory.
The company continues to update its advisory, noting on Sunday that its teams are still working on an official release that patches CVE-2026-82078 and CVE-2026-81578.
WatchTowr reported discovering multiple patch bypasses and an additional authentication bypass flaw, which triggered the second emergency patch.
Huntress has seen attacks against at least two customers, with the first exploitation attempts seen on August 26.
“Observed activity focused on system discovery,” Huntress noted. “We have not observed secondary malware, further command-and-control traffic, or additional persistence or post-exploitation from the recovered payload.”
It’s currently unclear who is behind the attacks exploiting the PaperCut NG/MF zero-days or what their motivation is.
Threat actors exploiting PaperCut NG/MF vulnerabilities is not unheard of. CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three other flaws, two of which have been exploited in ransomware attacks.
Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation.
Related: OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild

