Vulnerability

PaperCut issues second emergency patch for actively exploited CVEs

⏱️ 3 min read📅 8/29/2026👁️ 14 views

What happened and why it matters

PaperCut rolled out Emergency Patch Release 2 after security researchers confirmed active exploitation of two high‑severity bugs in its NG and MF print‑management suites.

Technical details

The update covers versions 24, 25 and 26 on Windows, Linux and macOS. It fixes:

  • CVE‑2026‑81578 – an authentication bypass (CVSS 8.8).
  • CVE‑2026‑82078 – unsafe dynamic class‑loading that leads to remote code execution (CVSS 9.4).

Both flaws can be chained: an attacker first sidesteps authentication, then leverages the class‑loading flaw to run arbitrary code on the server.

watchTowr and Huntress collaborated with PaperCut to reproduce the chain. Huntress saw the exploit in the wild in two customer environments and was able to trigger the full pre‑authentication RCE sequence.

Who’s affected

Any organization running PaperCut NG or MF version 24‑26 on any supported OS is in scope. The same product line was hit in 2023 when CVE‑2023‑27350 was abused by groups such as Clop, LockBit, Iranian state‑backed actors and the Bl00dy Ransomware Gang.

Immediate defensive steps

PaperCut’s own advisory recommends a short list of mitigations while the patch is applied:

  1. Limit web‑interface access to a whitelist of trusted IP addresses.
  2. Watch the pc‑app.exe process for unusual activity.
  3. Check server.log for missing or truncated entries.
  4. Alert on the following error strings:
    • “ERROR No suitable driver found for jdbc:no:x”
    • “ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST”
  5. Deploy Emergency Patch Release 2 without delay on all affected servers.

Once patched, continue to monitor for any residual indicators and apply the forthcoming IOCs once PaperCut publishes them.

#PaperCut#CVE-2026-81578#CVE-2026-82078#Emergency Patch#Print Management#Exploitation