Print-management vendor PaperCut released a second emergency patch (Emergency Patch Release 2) for its widely deployed PaperCut NG and MF software on August 28, 2026. The move followed the discovery of multiple ways to bypass the original fix issued on August 27. According to several security firms, two chainable vulnerabilities are already being actively exploited for unauthenticated remote code execution (pre-auth RCE).
Two flaws, one attack chain
The advisory centers on two vulnerabilities. CVE-2026-82078 (CVSS 9.4) is a critical unsafe dynamic class-loading flaw in the database connection utilities that allows execution of arbitrary Java bytecode. CVE-2026-81578 (CVSS 8.8) is an improper access-control issue in the web management interface that lets an unauthenticated attacker modify system configurations. Combined, the two form a complete pre-auth RCE chain. Security firm Huntress observed active exploitation in two customer environments on August 26 and 27, while watchTowr reproduced the flaws and identified additional techniques to bypass the initial patch.
Affected versions and recommended action
All NG/MF versions released before August 27, 2026 are affected. PaperCut provides Emergency Patch Release 2 for the 24, 25 and 26 branches on Windows, Linux and macOS; anyone still on version 23 or older should upgrade to a current release.
- Install Release 2 even if the first patch was already deployed.
- Restrict web interface access to trusted IP addresses via firewall rules.
- Hunt for compromise: suspicious
pc-app.exeactivity, missingserver.logfiles, and unusual database error messages.
Sources: BleepingComputer, Huntress, PaperCut Security Bulletin



















