Skip to main content
← Back to blog

PaperCut NG/MF Zero-Day Chain: Emergency Patch Release 2 Is Now Required

PaperCut confirmed active exploitation and issued a second emergency update after researchers found bypasses in the first fix. Organizations running PaperCut NG/MF should deploy Release 2 immediately, restrict web admin exposure, and review indicators tied to pre-auth compromise attempts.

#papercut#cve#zeroday#rce#patchmanagement#printsecurity
PaperCut NG/MF Zero-Day Chain: Emergency Patch Release 2 Is Now Required

PaperCut NG/MF Active Exploitation: Why Release 2 Matters

What happened

PaperCut disclosed that attackers were exploiting a vulnerability chain against PaperCut NG/MF and initially shipped an emergency patch. After collaborative analysis with researchers, additional bypass paths were identified, prompting a second emergency release with hardening.

Who is affected

Organizations operating PaperCut NG/MF servers on Windows, Linux, or macOS are affected, especially environments exposing management interfaces to broader networks.

Why it matters

Print management systems often hold privileged integration paths into enterprise identity and endpoint workflows. A pre-auth compromise path can lead to remote code execution and lateral movement opportunities in production networks.

Technical details

  • CVE-2026-81578: authentication bypass in NG/MF web management context (CVSS 8.8)
  • CVE-2026-82078: unsafe dynamic class loading leading to Java code execution conditions (CVSS 9.4)
  • Attack context: vulnerabilities can be chained for unauthenticated RCE
  • Exploitation status: confirmed active exploitation in real environments
  • Patch status: Emergency Patch Release 2 is the vendor-recommended remediation baseline

Recommended actions

  • Install Emergency Patch Release 2 immediately, even if Release 1 was already applied.
  • Upgrade unsupported older branches to current maintained versions.
  • Restrict PaperCut administrative web access to trusted IP ranges and segmented admin networks.
  • Hunt for post-exploitation indicators in PaperCut logs and endpoint telemetry around app server processes.
  • Validate that secondary/print servers are also updated where applicable.

Sources

  • https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/
  • https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/