PaperCut has released Emergency Patch Release 2 for PaperCut NG and MF after researchers found ways to bypass the original fix for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078. The flaws can be chained to bypass authentication and achieve remote code execution, and PaperCut is urging customers to upgrade and restrict access to trusted IPs while it continues investigating the attacks. #PaperCut #CVE-2026-81578 #CVE-2026-82078
Keypoints
- PaperCut issued a second emergency patch for PaperCut NG and MF.
- Researchers found multiple ways to bypass the initial security fixes.
- CVE-2026-81578 is an authentication bypass flaw in the web management interface.
- CVE-2026-82078 is an unsafe dynamic class-loading flaw that can lead to code execution.
- Administrators should upgrade, restrict web access, and monitor for signs of compromise.