Cybersecurity

PaperCut Releases Second Emergency Patch for Exploited Vulnerabilities in NG and MF

PaperCut has released a second emergency patch to address two actively exploited vulnerabilities in its NG and MF print management software after methods were discovered to bypass the first fix. When chained together, the vulnerabilities allow authentication bypass and remote code execution on affected servers.

2026-08-28
4 min read
6 views
فريق تحرير certi.news
PaperCut Releases Second Emergency Patch for Exploited Vulnerabilities in NG and MF

PaperCut has released a second emergency security patch for PaperCut NG and MF after researchers discovered several ways to bypass the first fix for two vulnerabilities being exploited in real-world attacks. The company urges all customers to install Emergency Patch Release 2, even if they have already applied the previous emergency patch.

PaperCut initially warned of zero-day attacks against customer servers and issued an initial fix for NG and MF versions 25 and 26 without publishing CVE numbers or technical details, to give customers time to apply the fixes and continue the investigation. In its latest update, the company disclosed that the vulnerabilities are tracked as CVE-2026-81578 and CVE-2026-82078.

Two Vulnerabilities That Can Be Chained for Remote Command Execution

CVE-2026-81578 is classified as high severity with a score of 8.8 and exists in the web-based administration interface of PaperCut NG and MF. According to PaperCut's description, under certain conditions, unauthenticated remote requests can target administrative functions and trigger background procedures before authorization checks are completed.

CVE-2026-82078 is classified as critical with a score of 9.4 and exists in database connectivity tools. The applications load database driver classes based on configurable names without checking them against an allowlist. If an attacker can modify system configuration parameters, this may result in the execution of arbitrary Java bytecode located within the application's classpath, with the privileges of the PaperCut server process.

watchTowr said that an unauthenticated attacker could use the two vulnerabilities to bypass authentication and achieve remote code execution. Huntress also reported observing exploitation in two customer environments and fully reproducing the pre-authentication code execution chain.

Why Is the First Patch No Longer Sufficient?

watchTowr explained that its researchers reproduced the vulnerabilities and discovered several ways to bypass the original patches, as well as another authentication-bypass vulnerability whose details they shared with PaperCut. Based on additional analysis conducted by PaperCut's internal teams in collaboration with Huntress and watchTowr, the second release includes additional hardening measures beyond the first fix.

Huntress said that PaperCut logs captured commands used by attackers to survey systems. The logs also contained Java files in .class format and encoded in hexadecimal, which were used as a bridge to execute commands and read or write files on the operating system. According to the company, the observed commands did not appear to be intended to deploy malware or establish persistence.

Affected Versions and Response Measures

Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Customers using version 23 or earlier must upgrade to the latest version rather than wait for a patch for those versions. The upgrade also includes secondary servers, print servers, and Site Servers, while the Print Deploy and Mobility Print components are not affected and do not require an update, according to the company.

  • Restrict access to web interfaces to trusted IP addresses using firewalls or network access controls.
  • Search for suspicious activity originating from the pc-app.exe process.
  • Examine server.log for missing or truncated files and for the following two error messages: ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
  • Review intrusion detection, endpoint monitoring, and network monitoring alerts associated with the PaperCut Application Server.

What Matters to System Administrators?

The most important practical development is that installing the first patch does not guarantee that the risk has been addressed, because researchers were able to identify ways to bypass it. System administrators should therefore treat the second release as a required fix, alongside reducing exposure of administrative interfaces and checking for indicators of compromise. PaperCut is still investigating what the attackers did after the compromise and has not identified those responsible for the attacks or published final indicators of compromise, stating that the activity appears limited and targeted so far.

The incident is particularly significant given that PaperCut servers were previously targeted in 2023 through CVE-2023-27350, an authentication-bypass and remote-code-execution vulnerability. However, the source does not establish that the same entities or methods are behind the current attacks, and details of the post-compromise activity remain under investigation.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news