Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The iPhone Fold could make concerts even worse

    August 29, 2026

    PaperCut releases second emergency patch for exploited flaws

    August 29, 2026

    Bitcoin Cools Off After $3 Billion ETF-Driven Surge

    August 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The iPhone Fold could make concerts even worse
    • PaperCut releases second emergency patch for exploited flaws
    • Bitcoin Cools Off After $3 Billion ETF-Driven Surge
    • The race to stop England running out of water
    • Fair pay, service charges and the pressure to tip | Social etiquette
    • Lake Ontario isn’t named after Canadian province
    • US and Venezuela reach ‘historic’ oil deal, Trump says
    • What it’s like to live through Kyiv’s constant air raids – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    PaperCut releases second emergency patch for exploited flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 29, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes.

    As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency patch for PaperCut NG/MF versions 25 and 26.

    At the time, however, the company had not disclosed CVE identifiers or technical details about the vulnerabilities, saying it was withholding information while it investigated the attacks and gave customers time to apply emergency fixes.

    image

    PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers.

    CVE-2026-81578 is a high-severity authentication bypass vulnerability rated 8.8 that impacts the PaperCut NG/MF web management interface.

    “Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks,” explains PaperCut’s updated advisory.

    The second vulnerability, tracked as CVE-2026-82078, is a critical unsafe dynamic class-loading flaw rated 9.4 that exists in PaperCut’s database connection utilities.

    The application loads database driver classes based on configurable driver names without validating them against an approved allowlist. 

    “If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process,” explains PaperCut.

    Cybersecurity firm watchTowr, which has been working with PaperCut during the incident, said on LinkedIn that the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances.

    Second emergency patch released

    On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr.

    “Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch,” PaperCut said.

    The company is urging all customers to install Release 2 even if they already installed the first emergency patch.

    This second release comes after watchTowr said its researchers fully reproduced the vulnerabilities, discovered multiple patch bypasses, and identified an additional authentication bypass vulnerability.

    Huntress, which has been working with PaperCut during the incident, says it observed exploitation in two customer environments and reproduced the full pre-authentication RCE chain.

    The company told BleepingComputer that PaperCut logs captured commands used by the attackers for system reconnaissance, while hex-encoded Java `.class` files found in the logs acted as an RCE bridge between PaperCut and the underlying operating system, allowing commands to be executed and files to be read or written.

    The commands observed by Huntress appear to have been used for reconnaissance rather than to deploy malware or establish persistence.

    Huntress also says it discovered multiple bypasses for the original emergency patches and an additional authentication bypass vulnerability, which it shared with PaperCut.

    Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Customers running version 23 or earlier are advised to upgrade to the latest version rather than wait for a patch for those releases.

    PaperCut says Site Servers and secondary/print servers should also be upgraded to patched versions. Other components, like Print Deploy and Mobility Print, are not affected and do not require updates.

    Even though patches are available, PaperCut to urge customers to restrict access to the web interfaces to trusted IP addresses using firewall rules, network access controls, or equivalent measures.

    Administrators should also look for suspicious post-exploitation activity from the pc-app.exe process, missing or truncated server.log files, and the following errors in the server.log.

    
    ERROR No suitable driver found for jdbc:no:x
    ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

    The company has not disclosed who is behind the attacks or what threat actors are doing after compromising vulnerable servers.

    PaperCut told BleepingComputer that the attacks appear limited and targeted, and that it is withholding details about post-exploitation activity while it continues its investigation.

    “Our investigation into what attackers are doing post-compromise is still active, and premature detail could complicate any affected customers’ own response,” PaperCut told BleepingComputer.

    “What we can say: the bulletin advises customers to watch for intrusion-detection, endpoint, or network-monitoring alerts tied to the PaperCut Application Server, and we’ll publish indicators of compromise as they’re verified.”

    PaperCut servers were previously targeted in 2023 after attackers began exploiting CVE-2023-27350, an authentication bypass and remote code execution vulnerability.

    Those attacks were ultimately linked to numerous threat actors, including the Clop and LockBit ransomware operations, Iranian state-backed hacking groups, and the Bl00dy Ransomware Gang.

    Update: Added information from Huntress.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    emergency Exploited flaws PaperCut patch Releases
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    McKesson discloses breach after ShinyHunters claims patient data theft

    Offensive Security Investments Surge as AI Threats Increase

    Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

    Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

    In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

    Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The iPhone Fold could make concerts even worse

    August 29, 2026

    PaperCut releases second emergency patch for exploited flaws

    August 29, 2026

    Bitcoin Cools Off After $3 Billion ETF-Driven Surge

    August 29, 2026

    The race to stop England running out of water

    August 29, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The iPhone Fold could make concerts even worse

    August 29, 2026

    PaperCut releases second emergency patch for exploited flaws

    August 29, 2026

    Bitcoin Cools Off After $3 Billion ETF-Driven Surge

    August 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.