ON August 27, 2026, PaperCut Software issued an urgent security advisory about a critical vulnerability in its printing management systems, PaperCut NG and PaperCut MF. This zero-day exploit, which affects all versions, allows attackers to bypass authentication and execute remote code. Two CVE identifiers were later assigned: CVE-2026-81578 for authentication bypass and CVE-2026-82078 for unsafe dynamic class loading.
Organizations are urged to patch their systems immediately, especially if their servers are internet-accessible. PaperCut has released emergency patches and advises restricting web access to trusted IPs. Past vulnerabilities highlight the serious need for timely remediation.