
PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws
PaperCut released Emergency Patch Release 2 to address two actively exploited flaws in NG/MF—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading leading to remote code execution). The update adds hardening beyond the first patch and is required for NG/MF 24–26; customers should upgrade (and restrict web interface access with firewalls) while investigators track post-exploitation activity and IOCs.













