PaperCut Releases Emergency Patch Release 2 for Actively Exploited Flaws

PaperCut confirmed the active exploitation of two flaws in NG and MF. Emergency Patch Release 2 is also intended for organizations that have already deployed the original emergency patch.

PaperCut Emergency Patch Release 2 mitigates the risk of two vulnerabilities in PaperCut NG and PaperCut MF products that, according to the vendor, are being actively exploited in incidents affecting customers. The emergency patch is available for branches 24, 25, and 26 on Windows, Linux, and macOS systems. The vendor recommends deploying it to organizations that have already applied the original emergency patch.

These are CVE-2026-81578 and CVE-2026-82078. The Canadian Centre for Cyber Security independently warned that both vulnerabilities are being actively exploited in the wild and that Emergency Patch Release 2 is the available remediation for versions 24 through 26.

What PaperCut Emergency Patch Delivers

CVE-2026-81578 allows authentication to be bypassed. An unauthenticated remote attacker can therefore modify selected system configurations. The second flaw, CVE-2026-82078, concerns unsafe dynamic class loading in database tools.

According to PaperCut, a combination of configuration manipulation and the second flaw could lead to the execution of arbitrary Java code in the context of the server process. The risk primarily affects PaperCut NG/MF servers accessible from the internet, which an attacker can target without credentials.

PaperCut published Emergency Patch Release 2 on August 28. As of August 31, the vendor also stated that it was continuing to work on the full official patch release; however, it describes the available emergency package as a mitigation that should be applied without waiting.

Recommended Steps for Administrators

Organizations operating affected installations should deploy Emergency Patch Release 2 for versions 24, 25, or 26. Importantly, according to the current recommendation, the first emergency patch alone is not sufficient.

Until the risk can be reduced through patching, PaperCut recommends immediately blocking access to the PaperCut Application Server web interfaces from untrusted internet addresses.

The vendor also added indicators of compromise. These include suspicious activity involving the pc-app.exe process, unusually shortened or missing server.log files, and specific strings or files with .class, .cmd, and .out extensions. These indicators are intended to help administrators investigate suspicious activity.

Exploitation Confirmed, Scope Unclear

PaperCut confirmed incidents affecting customers as well as active exploitation of the flaws. However, the attackers’ identities, motives, and the total number of affected organizations are not known.

Subsequent activity following compromise also remains incompletely understood. In some cases, PaperCut observed reconnaissance commands and the deployment of remote-access tools, but this is not a confirmed universal procedure in all incidents.

For administrators of corporate, school, and public networks, the key priorities now are verifying the PaperCut version, deployment of Emergency Patch Release 2, and the availability of administrative interfaces from the internet. Further information may concern the full official patch, support for older versions, and new forensic findings from the vendor.

Sources

Verified and updated: 08/31/2026 10:49

Sharing