PaperCut releases second emergency patch for exploited vulnerabilities

PaperCut releases second emergency patch for exploited vulnerabilities

PaperCut

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its print management software PaperCut NG and MF, after researchers discovered several ways to bypass the initial fixes.

As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks on customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.

However, at the time, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it had withheld information while investigating the attacks and given customers time to make emergency fixes.

Picture

PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be due to bypassing authentication and executing code on vulnerable servers.

CVE-2026-81578 is a high-severity 8.8 authentication bypass vulnerability that impacts the web administration interface of PaperCut NG/MF.

“Under certain conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions before access validation checks are completed,” explains PaperCut’s updated recommendation.

The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class loading flaw with a rating of 9.4 that exists in PaperCut’s database connection utilities.

The application loads database driver classes based on configurable driver names without validating them against an approved allowlist.

“If an attacker can manipulate system configuration parameters, this allows the execution of arbitrary Java bytecode located in the application classpath in the security context of the PaperCut server process,” explains PaperCut.

Cybersecurity company watchTowr, which worked with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances.

Second emergency patch released

On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers from Huntress and watchTowr.

“After further collaboration with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated emergency patch (Release 2) that includes additional hardening beyond the original emergency patch,” PaperCut said.

The company urges all customers to install Release 2, even if they have already installed the first emergency patch.

This second release comes after watchTowr said its researchers have fully reproduced the vulnerabilities, discovered multiple patch workarounds, and identified an additional authentication bypass vulnerability.

BleepingComputer has reached out to Huntress to learn more about what its researchers discovered when analyzing the vulnerabilities and will update the story if we receive a response.

Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25 and 26 on Windows, Linux and macOS. Customers using version 23 or earlier are recommended to update to the latest version rather than waiting for a patch for these versions.

PaperCut says site servers and secondary/print servers should also be updated to patched versions. Other components such as Print Deploy and Mobility Print are not affected and do not require updates.

Although patches are available, PaperCut strongly recommends that customers limit access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures.

Administrators should also look for suspicious post-exploitation activities in the pc-app.exe process, missing or truncated server.log files, and the following server.log errors.


ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

The company has not disclosed who is behind the attacks or what the threat actors do after compromising vulnerable servers.

PaperCut told BleepingComputer that the attacks appear to be limited and targeted, and that the company is withholding details about post-exploitation activity while the investigation continues.

“Our investigation into what attackers do after the compromise is still active, and premature details could complicate affected customers’ own response,” PaperCut told BleepingComputer.

“What we can say: The bulletin advises customers to be alert for intrusion detection, endpoint or network monitoring alerts related to the PaperCut Application Server, and we will publish indicators of compromise as they are reviewed.”

PaperCut servers were targeted back in 2023 after attackers began exploiting CVE-2023-27350, an authentication bypass and remote code execution vulnerability.

These attacks were ultimately linked to numerous threat actors, including the Clop and LockBit ransomware operations, Iranian state-backed hacking groups, and the Bl00dy Ransomware Gang.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *