PaperCut NG/MF Vulnerabilities Are Being Actively Exploited; Vendor Releases Third Emergency Patch
PaperCut confirmed incidents involving the active exploitation of two vulnerabilities in PaperCut NG and MF systems. Organizations should deploy Emergency Patch Release 3, restrict public access, and check for indicators of compromise.

Vulnerabilities in PaperCut NG/MF are being actively exploited, the vendor confirmed following incidents affecting PaperCut customers. The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, can be chained so that an unauthenticated attacker changes selected configurations and subsequently executes arbitrary Java code in the context of the PaperCut process. On September 1, the vendor released Emergency Patch Release 3 and recommended immediately checking exposed servers.
The U.S. agency CISA added both flaws to its Known Exploited Vulnerabilities (KEV) catalog on August 31. PaperCut also said it has recorded customer incidents related to the active exploitation of PaperCut NG and PaperCut MF products.
PaperCut NG/MF Vulnerabilities Can Be Chained
The first flaw, CVE-2026-81578, allows unauthenticated changes to selected configurations. This capability may create an opportunity to exploit the second vulnerability, CVE-2026-82078, which may subsequently lead to the execution of arbitrary Java code in the context of the PaperCut process.
Unpatched PaperCut NG/MF servers can be attacked remotely without authentication. If the flaws are successfully chained, an attacker can execute code on the server.
Release 3 Replaces the Earlier Emergency Patch
PaperCut released Emergency Patch Release 3 on September 1. According to the vendor, this version replaces the previous Release 2 and includes additional hardening and mitigations. Organizations should therefore deploy the current Release 3.
Alongside the update, the vendor recommends immediately restricting access to the web interfaces of publicly accessible Application Servers. The interfaces should be accessible only from trusted IP addresses.
- Deploy Emergency Patch Release 3 for PaperCut NG or PaperCut MF.
- Restrict access to the Application Server web interface to trusted IP addresses.
- Check logs and systems for the indicators of compromise listed by the vendor.
- Check endpoints and servers related to PaperCut operations.
What Administrators Should Focus On
PaperCut warns of suspicious activity involving the pc-app.exe process, changes to or disappearance of the server.log file, and the presence of files with .class or .cmd extensions in installation directories. These signs should be investigated in the context of the specific environment and the vendor’s procedures.
The identity of the attackers, the campaign’s overall scope, and the full list of post-compromise activities have not been confirmed. The available documentation also does not independently confirm in detail the claim that current campaigns demonstrably serve to steal data.
The immediate priority remains updating PaperCut and restricting access to publicly exposed interfaces.
Sources
- PaperCut — URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) – The vendor confirms active exploitation and customer incidents, describes both CVEs, lists indicators of compromise, and announces Emergency Patch Release 3.
- Canadian Centre for Cyber Security — PaperCut security advisory (AV26-858) – Update 2 – Confirms active exploitation and the addition of CVE-2026-81578 and CVE-2026-82078 to CISA KEV on August 31, 2026.
- NHS England — PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF – Corroborates active exploitation, the ability to change configurations and subsequently execute code, and the recommendation to remove public exposure.
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws – Corroborates the chaining of the flaws, observed attacks in customer environments, and earlier emergency patches.
Verified and updated: 09/01/2026 15:08



