PaperCut patches NG/MF zero-day under active attack
PaperCut confirmed active exploitation of a two-bug chain in NG and MF and shipped Emergency Patch Release 2. An auth bypass (CVE-2026-81578) enables arbitrary Java code (CVE-2026-82078). Install Release 2 even if you already applied Release 1.

PaperCut has confirmed active exploitation of a vulnerability chain in its NG and MF print-management software and shipped an emergency fix, per its security bulletin. The important nuance up front: this is a two-bug chain, and the fix is a specific one. Emergency Patch Release 2 is required even if you already applied the first emergency patch, so an admin who patched earlier this week is not necessarily covered.
The immediate action, before the CVE detail
If your PaperCut Application Server is reachable from the internet, the bulletin's first instruction is not "patch," it is "restrict." Limit web access to trusted IP addresses now, then patch. The advisory reports confirmed customer incidents, so exposure, not just vulnerability, is the live risk. Release 2 builds are available for the v26, v25, and v24 families across Windows, Linux, and macOS, with SHA256 hashes on the bulletin.
The two instruments, in the right order
Name these precisely, because the order is the whole story.
CVE-2026-81578 is an authentication bypass in the web management interface, an improper-access-control flaw (CWE-306) rated CVSS 8.8 High. On its own it lets an unauthenticated remote attacker modify certain system configurations. It is not remote code execution by itself, and calling it that misses how the attack works.
CVE-2026-82078 is the code-execution half: unsafe dynamic class loading in the database connector (CWE-470), rated CVSS 9.4 Critical on CVSS 4.0. Its impact is arbitrary Java bytecode execution, but only if an attacker can manipulate the system configuration first.
That "first" is the link. According to Help Net Security, Huntress and watchTowr found the two chained in real attacks: the auth bypass grabs configuration control, which then unlocks the class-loading bug for code execution. Huntress said it reproduced a pre-authentication remote configuration takeover and a complete remote code execution chain against a stock install of PaperCut NG 25.0.11.75758, and observed base64-encoded reconnaissance commands (whoami and ver) on two victim environments. Neither bug is the story alone; the chain is.
What to hunt for
Do not stop at patching; assume the reachable servers were probed. The bulletin lists indicators of compromise worth grepping for today: a pc-app.exe process from post-exploitation, a truncated or deleted server.log (attackers clearing tracks), and error lines reading "No suitable driver found for jdbc:no:x" and "DatabaseUtils - Database error looking up cardID: VALUES CAST." PaperCut says its investigation is ongoing and it is still updating indicators, so treat the current list as a floor, not a complete set.
The takeaway
The decision is sequencing, and it is time-boxed. Right now, put trusted-IP restrictions in front of any internet-reachable PaperCut Application Server; that closes the exposure while you stage the update. Then install Emergency Patch Release 2 specifically, confirming the build even on servers you patched earlier, because Release 1 did not close this. Then search logs and processes for the IoCs above before you call it done, since confirmed customer incidents mean some of these servers were already reached. Patch order here is not housekeeping; it is the difference between closing the door and closing it after someone walked through.
For related exploitation and KEV context this week, see our coverage of CISA adding NetScaler and SQL Server flaws to KEV, the DOJ and FBI seizure of the QScan and QTRouter platforms, and the Gitea CVE-2026-60004 KEV addition.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free