Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Alert! PaperCut issues emergency patches for PaperCut NG and PaperCut MF, warns active exploitation underway

The print management firm warns of two vulnerabilities in its software, with one expert calling the company’s platforms a “sensitive information treasure trove”.

Mon, 31 Aug 2026
Alert! PaperCut issues emergency patches for PaperCut NG and PaperCut MF, warns active exploitation underway

Printing software firm PaperCut has issued emergency patches for a pair of serious vulnerabilities in its PaperCut NG and PaperCut MF print management platforms, while warning that its customers are already being targeted by malicious activity.

“We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” PaperCut said in its advisory.

“We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.”

 
 

PaperCut released an urgent security advisory on 27 August, when it first said it was aware of active exploitation and that it was treating the situation as a security emergency. At the time, no CVEs had been assigned, nor had CVSS scores, but that changed on 28 August.

CVE-2026-81578 is an authentication bypass vulnerability with a CVSS score of 8.8, while CVE-2026-82078 is an unsafe dynamic class loading in database connector flaw, with a CVSS score of 9.8.

An emergency patch was released the same day, and by 30 August, PaperCut was still working on an official release. Until then, all unpatched versions of both platforms are potentially impacted.

Cyber security firm Rapid7 published an Emergency Threat Response blog explaining how the exploits work, a day after PaperCut disclosed its difficulties.

“The vulnerability is an authentication bypass that lets attackers invoke privileged PaperCut components,” Rapid7 said.

“This can be leveraged to reconfigure an external database lookup. When this lookup is triggered, malicious SQL can be executed, resulting in remote code execution.”

Exposure management firm watchTowr managed to reproduce the vulnerabilities and is actively assisting PaperCut. The company said the situation is evolving rapidly and that the threat remains very real.

“PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated,” Jake Knott, watchTowr’s head of threat intelligence, told Cyber Daily.

“Organisations with vulnerable internet-facing instances of PaperCut need to remove public internet access where possible, and begin hunting for signs of compromise, such as looking for ‘Database error looking up cardID: VALUES CAST’ errors in log files.

“This is not a vulnerability you want to wait on change control, CVE assignment, or a ransom note to hit your desktop before applying a patch, and removing public internet access.”

PaperCut is used by several Australian organisations, including the University of Melbourne and Baker’s Delight.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: