"Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch," PaperCut said.
CVE-2026-81578 and CVE-2026-82078: technical specifics
PaperCut has publicly identified two vulnerabilities that were being actively exploited in PaperCut NG and MF installations: CVE-2026-81578 and CVE-2026-82078. The first, CVE-2026-81578, is rated 8.8 and described as an authentication bypass that "under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks," according to PaperCut's updated advisory.
The second, CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4. PaperCut explains the application loads database driver classes based on configurable driver names without validating them against an approved allowlist. "If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process," the company wrote.
Emergency Patch Release 2 and deployment guidance
PaperCut released Emergency Patch Release 2 after further analysis with its internal security team and external researchers. The company is urging all customers to install Release 2 even if they already installed the first emergency patch. Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS.
Customers running version 23 or earlier are advised to upgrade to the latest version rather than wait for a patch for those releases. PaperCut also told customers that Site Servers and secondary/print servers should be upgraded to patched versions.
PaperCut noted that other components, specifically Print Deploy and Mobility Print, are not affected and do not require updates. Even with patches available, the company urged customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow the flaws were reproduced, chained, and what to look for
Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances. watchTowr told PaperCut and others it fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass.
PaperCut advised administrators to look for signs of post-exploitation activity tied to the PaperCut Application Server, including suspicious activity from the pc-app.exe process, missing or truncated server.log files, and specific server.log errors such as:
- ERROR No suitable driver found for jdbc:no:x
- ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
PaperCut said its investigation into what attackers are doing post-compromise is ongoing and that it is withholding some details to avoid complicating affected customers' responses. "Our investigation into what attackers are doing post-compromise is still active, and premature detail could complicate any affected customers' own response," PaperCut told BleepingComputer. The company added it will publish indicators of compromise as they are verified.
Role of watchTowr and Huntress in the incident response
PaperCut credited further analysis with its internal team and external researchers at Huntress and watchTowr as the reason for the additional hardening in Release 2. BleepingComputer reported that it reached out to Huntress for more detail on the research findings; that outreach was noted as pending an updated response. watchTowr's public statements on LinkedIn were the source for the claim that the vulnerabilities permit unauthenticated bypass and remote code execution.
What this means for technologists, procurement leaders, and administrators
- Technologists and security teams: Install Emergency Patch Release 2 on affected versions 24–26 across Windows, Linux, and macOS; upgrade older installations (version 23 or earlier) to the latest release rather than awaiting backports; restrict web-interface access to trusted IP ranges; and monitor intrusion-detection, endpoint, and network-monitoring alerts tied to the PaperCut Application Server.
- Procurement and IT leaders: Ensure inventories identify all PaperCut NG/MF instances, including Site Servers and secondary/print servers, and confirm those components are updated or scheduled for upgrade. Note that Print Deploy and Mobility Print were specifically called out as not affected.
- Administrators and operations teams: Watch for the specific server.log errors PaperCut cited, look for truncated or missing server.log files and unusual pc-app.exe behavior, and be prepared to apply the Release 2 patch even if the first emergency patch was already installed.
PaperCut has not disclosed which actors are behind the current attacks or the full scope of post-compromise activity. The company characterized the attacks as limited and targeted, and said indicators of compromise will be published as they are verified. PaperCut servers were previously targeted in 2023 after attackers exploited CVE-2023-27350; those attacks were later linked to multiple threat actors including Clop, LockBit, Iranian state‑backed hacking groups, and the Bl00dy Ransomware Gang. For now, the concrete steps are clear: deploy Release 2, tighten access controls, and monitor the specific indicators PaperCut has published while investigators continue to verify further details.




