PaperCut Releases Second Emergency Update for Actively Exploited Vulnerabilities
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software. This intervention follows the discovery of several methods to bypass the initial fixes, as reported by BleepingComputer.
Initially, PaperCut had warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and had released an emergency patch for versions 25 and 26 of PaperCut NG/MF. However, the company had not provided CVE identifiers or technical details about the vulnerabilities, stating that it was withholding information while investigating the attacks and giving customers time to apply the emergency fixes.
Technical Details of the Vulnerabilities
PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers.
CVE-2026-81578 is a high-severity authentication bypass vulnerability, rated 8.8, affecting the web management interface of PaperCut NG/MF. As explained in PaperCut's updated advisory, "under specific conditions, unauthenticated remote requests directed to administrative functions can trigger backend actions before the completion of access validation checks."
The second vulnerability, tracked as CVE-2026-82078, is a critical insecure dynamic class loading defect, rated 9.4, that exists in PaperCut's database connection utilities. The application loads database driver classes based on configurable driver names without validating them against an approval list.
"If an attacker can manipulate system configuration parameters, this allows the execution of arbitrary Java bytecode present in the application path under the security context of the PaperCut server process," explains PaperCut.
The cybersecurity firm watchTowr, which collaborated with PaperCut during the incident, stated on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.
Release of the Second Emergency Update
On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers from Huntress and watchTowr.
"After further work with our internal security team and researchers from Huntress and watchTowr, we have released Emergency Patch Release 2 to address these vulnerabilities," the company stated.
PaperCut recommended that customers apply the update immediately and review their system logs for any signs of exploitation.
Impact on the Cybersecurity Landscape
The discovery and exploitation of vulnerabilities in PaperCut NG and MF have raised significant concerns in the cybersecurity sector. Experts emphasize that these vulnerabilities, especially when chained, pose a high risk to enterprise infrastructures that use the software for print management.
Analyses by Huntress and watchTowr have highlighted that attackers are exploiting these flaws to conduct reconnaissance activities, a behavior that could precede more devastating attacks such as ransomware or the extraction of sensitive data. The targeted nature of the attacks suggests that threat actors may have specific objectives, such as organizations with critical data or sensitive infrastructure.
Security experts recommend closely monitoring PaperCut systems for signs of suspicious activity, even after applying the patches. The combination of preventive measures, such as limiting access to web interfaces, and constant vigilance could mitigate the risk of further compromises.
Implications for System Administrators
For system administrators, managing these vulnerabilities requires a proactive approach. In addition to immediately applying Emergency Patch Release 2, it is crucial to conduct a comprehensive audit of existing configurations to ensure there are no other security gaps.
PaperCut advised examining system logs to identify any specific errors that could indicate post-exploitation activity. However, the lack of complete details on indicators of compromise from PaperCut complicates the detection and response process.
Administrators should also consider implementing advanced monitoring solutions, such as intrusion detection systems (IDS) and behavioral analysis, to identify anomalies that might evade traditional controls.
Emerging Trends in Attacks on Management Software
Attacks on management software like PaperCut are not isolated. In recent years, there has been an increase in attacks on third-party software that manages critical functionalities within enterprise networks. These software applications, often considered less critical than operating systems or security applications, become attractive targets for attackers.
The vulnerability CVE-2023-27350, exploited in 2023, demonstrated how seemingly innocuous software could become an entry point for complex attacks. The connection of these vulnerabilities to ransomware groups like Clop and LockBit underscores the importance of rigorous patch management and continuous risk assessment.
Experts predict that attacks on management software will continue to grow, pushing organizations to adopt more integrated security strategies and invest in continuous monitoring solutions.
Advice for Organizations
To mitigate the risks associated with these vulnerabilities, organizations should adopt the following measures:
- Update Immediately: Apply Emergency Patch Release 2 to all instances of PaperCut NG and MF.
- Limit Access: Use firewalls and network access controls to restrict access to PaperCut web interfaces to only trusted IP addresses.
- Monitor Closely: Implement advanced monitoring solutions to detect suspicious activity and analyze system logs for specific errors.
- Conduct Security Audits: Perform periodic assessments of security configurations and patch management practices.
- Prepare Response Plans: Develop and test incident response plans to quickly address any potential compromises.
Cybersecurity is a continuous process that requires vigilance and adaptability. The attacks on PaperCut serve as a warning to organizations worldwide, underscoring the importance of proactive vulnerability management and close collaboration with the security community.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.