PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two vulnerabilities in its print management software.
Intelligence analysis by Qwen 2.5 (3B)

PaperCut has released a second emergency patch for two vulnerabilities in its NG and MF print management software.
PaperCut has released a second emergency patch to fix two security issues in their print management software. One issue lets attackers trick the system into doing things they shouldn't, and the other lets them run their own code on the system. The company is urging all users to update their software to stay safe.
Analysis
{"#authentication_bypass_vulnerability":"PaperCut NG/MF web management interface is vulnerable to an authentication bypass vulnerability (CVE-2026-81578) that can be triggered under specific conditions. This vulnerability is rated 8.8 and exists due to backend actions being triggered before access validation checks are completed. Huntress and watchTowr researchers have identified multiple ways to bypass this vulnerability.","#unsafe_dynamic_class_loading_vulnerability":"The second vulnerability (CVE-2026-82078) is a critical unsafe dynamic class-loading flaw that exists in PaperCut's database connection utilities. Attackers can manipulate system configuration parameters to execute arbitrary Java bytecode, allowing remote code execution. Huntress and watchTowr researchers have identified multiple bypasses for this vulnerability.","#additional_authentication_bypass_vulnerability":"Huntress and watchTowr researchers have also identified an additional authentication bypass vulnerability, which they shared with PaperCut. This vulnerability allows attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances."}
Key points
- PaperCut has released a second emergency patch for two vulnerabilities in its NG and MF print management software.
- The vulnerabilities include an authentication bypass and an unsafe dynamic class-loading flaw.
- The second patch includes additional hardening developed after further analysis with internal security team and researchers.
The second emergency patch should help prevent attackers from exploiting the vulnerabilities and protect users' systems from potential attacks.
If attackers find a way to exploit the vulnerabilities, they could gain control of users' systems and cause damage. The company is still investigating the attacks and will provide more details as they become available.



