PaperCut issues updated emergency fix after researchers find bypasses for initial patch

PaperCut has released a second emergency update for two actively exploited vulnerabilities in its NG and MF print management software, tracked as CVE-2026-82078 and CVE-2026-81578. The flaws can be chained to bypass authentication and achieve remote code execution. The new patch includes additional hardening developed with security firms Huntress and watchTowr after multiple bypass methods were discovered.
The updated patch follows watchTowr’s full reproduction of the flaws, which uncovered multiple bypasses for the initial fix and an extra authentication bypass. Huntress observed real-world exploitation in two customer environments, with logs showing reconnaissance commands and hex-encoded Java class files used as a bridge to execute system-level actions. No malware or persistence was detected in those cases. PaperCut now urges all customers, even those who applied the first emergency patch, to install Release 2, which covers versions 24 through 26 across Windows, Linux, and macOS. Older versions are advised to upgrade.
This incident could affect any organization relying on PaperCut for print management, particularly schools and offices where such software is common. The chained vulnerabilities allow unauthenticated remote code execution, meaning attackers may gain full server control without credentials. While observed activity so far appears limited to reconnaissance, the potential for data theft, ransomware deployment, or lateral movement remains significant. Organizations that delayed patching or applied only the first fix may still be exposed, underscoring how quickly attackers adapt when initial mitigations are incomplete.