Already patched PaperCut? You need to do it again
The second patch is essential for security.

AI hackers. By GettyImages
- PaperCut released a second emergency patch for actively exploited flaws in PaperCut NG and MF.
- Customers should install Release 2 even if they already applied the first emergency patch.
- Researchers found ways to bypass the initial patch and reproduced a pre-login remote attack chain.
- PaperCut says attacks appear limited and targeted, while its investigation remains ongoing.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
PaperCut has released an urgent security advisory for actively exploited vulnerabilities affecting PaperCut NG and PaperCut MF. Users who have already installed the first emergency patch are urged to patch again.
PaperCut, a software system used by businesses, schools, and other organizations to manage printing, said it’s aware of confirmed customer incidents related to vulnerability exploitation.
The company is “treating this matter with the highest priority”, and the investigation remains ongoing.
The emergency patch is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. It includes “additional hardening” beyond the original emergency patch and is especially urgent for customers with public-facing PaperCut NG/MF servers.
“Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch,” PaperCut said.
Customers are advised to immediately restrict access to PaperCut’s web interfaces to trusted IP addresses and install the latest patch.
The company has publicly named two vulnerabilities: CVE-2026-82078 in PaperCut’s database connection utilities and CVE-2026-81578 in the web management interface of PaperCut MF and PaperCut NG.
The second patch comes after researchers from watchTowr fully reproduced the vulnerabilities and discovered multiple ways to bypass the initial patch.
Huntress cybersecurity experts were also able to reproduce the full pre-authentication RCE chain and observed exploitation in two customer environments, where attackers appeared to have been conducting reconnaissance. Huntress did not observe the attackers deploying malware or attempting to establish persistence.
The company lists a few signs of intrusion, including suspicious activity from the PaperCut Application Server, missing or deleted server logs, and unusual database errors in the logs. But it explicitly states that the absence of these signs does not mean the system is not affected.
PaperCut told BleepingComputer that the attacks appear limited and targeted, and that additional information is not being shared while the investigation is ongoing.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
"Our investigation into what attackers are doing post-compromise is still active, and premature detail could complicate any affected customers' own response," PaperCut said.
"What we can say: the bulletin advises customers to watch for intrusion-detection, endpoint, or network-monitoring alerts tied to the PaperCut Application Server, and we'll publish indicators of compromise as they're verified."