discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two vulnerabilities in its print management software.

By Lawrence Abrams·Aug 28·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

PaperCut releases second emergency patch for exploited flaws
Image: bleepingcomputer.com

PaperCut has released a second emergency patch for two vulnerabilities in its NG and MF print management software.

Why it matters

This patch is important for organizations using PaperCut NG and MF to secure their print management systems from potential attacks.

PaperCut has released a second emergency patch to fix two security issues in their print management software. One issue lets attackers trick the system into doing things they shouldn't, and the other lets them run their own code on the system. The company is urging all users to update their software to stay safe.

Analysis

{"#authentication_bypass_vulnerability":"PaperCut NG/MF web management interface is vulnerable to an authentication bypass vulnerability (CVE-2026-81578) that can be triggered under specific conditions. This vulnerability is rated 8.8 and exists due to backend actions being triggered before access validation checks are completed. Huntress and watchTowr researchers have identified multiple ways to bypass this vulnerability.","#unsafe_dynamic_class_loading_vulnerability":"The second vulnerability (CVE-2026-82078) is a critical unsafe dynamic class-loading flaw that exists in PaperCut's database connection utilities. Attackers can manipulate system configuration parameters to execute arbitrary Java bytecode, allowing remote code execution. Huntress and watchTowr researchers have identified multiple bypasses for this vulnerability.","#additional_authentication_bypass_vulnerability":"Huntress and watchTowr researchers have also identified an additional authentication bypass vulnerability, which they shared with PaperCut. This vulnerability allows attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances."}

Key points

  • PaperCut has released a second emergency patch for two vulnerabilities in its NG and MF print management software.
  • The vulnerabilities include an authentication bypass and an unsafe dynamic class-loading flaw.
  • The second patch includes additional hardening developed after further analysis with internal security team and researchers.
The Upside

The second emergency patch should help prevent attackers from exploiting the vulnerabilities and protect users' systems from potential attacks.

The Downside

If attackers find a way to exploit the vulnerabilities, they could gain control of users' systems and cause damage. The company is still investigating the attacks and will provide more details as they become available.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityprint-managementvulnerabilitiesauthenticationremote-code-execution

Author

Lawrence Abrams

Intelligence analysis by

Qwen 2.5 (3B)

Published

Aug 28, 2026

Source

bleepingcomputer.com

Share

Topics

securityprint-managementvulnerabilitiesauthenticationremote-code-execution

Related

More from this desk

Aug 28·bleepingcomputer.com

McKesson discloses breach after ShinyHunters claims patient data theft

McKesson discloses breach after ShinyHunters claims patient data theft. McKesson says 284 million patient data records were stolen.

Aug 28·thehackernews.com

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government refuses to pay extortionists who stole data from its state administrative network. Forensic work found further data outflows in the Senate Department for Mobility, Transport, Climate Protection and Environment.

Aug 28·thehackernews.com

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs warns of a critical balance-handling flaw in the shared Cosmos EVM module exploited to drain funds from six blockchains. Fix shipped in v0.6.2 and v0.7.2.

Aug 28·wired.com

Microsoft Teams Has Become a Haven for Scammers in China

Chinese scammers are using Microsoft Teams to carry out scams, with victims losing millions of dollars.