PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws

TL;DR Summary
PaperCut released Emergency Patch Release 2 to address two actively exploited flaws in NG/MF—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading leading to remote code execution). The update adds hardening beyond the first patch and is required for NG/MF 24–26; customers should upgrade (and restrict web interface access with firewalls) while investigators track post-exploitation activity and IOCs.
Topics:technology#authentication-bypass#emergency-patch#papercut#remote-code-execution#security#vulnerability
- PaperCut releases second emergency patch for exploited flaws BleepingComputer
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication The Hacker News
- PaperCut targeted by hackers Printweek
- PaperCut Releases Emergency Patch for Exploited Zero-Day SecurityWeek
- Warning: Critical and High vulnerability in PaperCut, Patch Immediately! CCB Belgium
Reading Insights
Total Reads
1
Unique Readers
7
Time Saved
5 min
vs 6 min read
Condensed
95%
1,086 → 58 words
Want the full story? Read the original article
Read on BleepingComputer