www.securityweek.com 8/31/2026, 7:01:31 AM · external

PaperCut rolls out second patch following zero day RCE attacks

PaperCut rolls out second patch following zero day RCE attacks
Developing story vulnerability 6 articles tracked
PaperCut NG/MF zero‑day RCE flaws (CVE-2026-81578, CVE-2026-82078) exploited
CyberSIXT Evidence Panel
Primary Source papercut.com
CISA KEV Not in KEV
Patch Patch Status Unknown

PAPERCUT Software has released a second emergency patch for vulnerabilities in its NG and MF print management solutions, which were exploited by attackers to achieve remote code execution. Initial reports mentioned one vulnerability, but two zero-days (CVE-2026-81578 and CVE-2026-82078) were confirmed. The first flaw involves an authentication bypass allowing unauthorized configuration changes, while the second pertains to unsafe class loading in database utilities.

Despite multiple patches being issued, some bypass attempts were reported. Approximately 1,000 PaperCut instances are still exposed online, primarily in North America and Europe, raising concerns about potential ransomware exploitation.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline