09/01/2026
Security Bulletin: PaperCut NG and PaperCut MF Vulnerabilities — Two vulnerabilities affecting PaperCut NG and MF are actively exploited in the wild, with PaperCut confirming customer incidents.
CVE-2026-82078 (CVSS 9.4) is an unsafe dynamic class loading vulnerability that may allow arbitrary Java bytecode ex*****on under the security context of the PaperCut server process.
CVE-2026-81578 (CVSS 8.8) is an improper access control vulnerability that may allow unauthenticated attackers to trigger administrative backend actions and modify certain system configurations.
PaperCut has released Emergency Patch Release 2, which supersedes the original emergency patch and adds additional hardening. Organizations should install Release 2 across all PaperCut NG and MF Application Servers, including Site Servers and secondary or print servers, even if the original emergency patch was already applied.
Teams should also review http://server.log, IDS, EDR, and network telemetry for indicators of exploitation or suspicious activity involving http://pc-app.exe.
https://hubs.li/Q04w8z160
PaperCut NG and MF vulnerabilities (CVE-2026-82078, CVE-2026-81578) may enable code ex*****on and unauthorized configuration changes. Actively exploited—install Emergency Patch Release 2.