PaperCut releases second emergency patch for exploited flaws
PaperCut has issued Emergency Patch Release 2 for its NG and MF print management platforms, addressing two vulnerabilities currently being exploited in the wild: CVE-2026-81578 and CVE-2026-82078. This urgent update follows discovery of multiple bypass techniques against the initial fix, allowing unauthenticated attackers to chain these flaws for full remote code execution. The advisory covers versions 24, 25, and 26 across Windows, Linux, and macOS, with older releases requiring a full upgrade.
CVE-2026-81578 is a high-severity authentication bypass (CVSS 8.8) in the web management interface, while CVE-2026-82078 is a critical flaw (CVSS 9.4) involving unsafe dynamic class loading in database utilities. Researchers at watchTowr and Huntress helped identify the initial attack vectors and subsequent bypasses. Administrators are strongly urged to install the new patch immediately, restrict web interface access via firewall rules, and monitor server logs for specific error strings indicating post-exploitation activity.