PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions, as more information about the vulnerabilities and their exploitation continues to emerge.
The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.
The vendor issued a security bulletin on August 27 and released the first emergency patch for PaperCut NG/MF versions 25 and 26 the next day. The second emergency patch was released later the same day to provide additional hardening, including for version 24. Indicators of Compromise (IoCs) were also provided.
Initially it was assumed that the attackers had exploited a single vulnerability, but PaperCut and the security firms monitoring the situation huntress And Watchtowerrevealed that two zero days were exploited.
One of them is tracked as CVE-2026-81578 and is described as a high-level authentication bypass that allows a remote, unauthenticated attacker to change certain system configurations.
The second flaw, CVE-2026-82078, is a critical issue related to unsafe dynamic class loading in the database connection utilities.
“If an attacker can manipulate system configuration parameters, this allows the execution of arbitrary Java bytecode located in the application classpath in the security context of the PaperCut server process,” PaperCut explained in its advisory.
The company continues to update its advisory, noting on Sunday that its teams are still working on an official release that patches CVE-2026-82078 and CVE-2026-81578.
WatchTowr reported the discovery of multiple patch bypasses and an additional authentication bypass flaw that triggered the second emergency patch.
Huntress has experienced attacks against at least two customers, with the first exploitation attempts occurring on August 26th.
“The activity observed was focused on system detection,” Huntress noted. “We did not observe any secondary malware, any additional command-and-control traffic, or any additional persistence or post-exploitation of the recovered payload.”
It is currently unclear who is behind the attacks exploiting the PaperCut NG/MF zero-days and what their motivation is.
It is not uncommon for threat actors to exploit PaperCut NG/MF vulnerabilities. Known CISA Exploited Vulnerabilities (KEV) catalog contains three additional vulnerabilities, two of which were exploited in ransomware attacks.
There are currently around 1,000 PaperCut instances exposed to the interneta majority in North America and Europe, according to the ShadowServer Foundation.
Related: OpenAI agents exploited Linux kernel flaws on company-owned systems
Related: Current vulnerability in Citrix NetScaler exploited
Related: Adobe and Nvidia patch dozens of security holes
