PaperCut has urged users of its PaperCut NG/MF platforms to apply a third emergency patch to all public-facing instances, as a pair of serious vulnerabilities continue to be actively exploited.
“Emergency Patch (Release 3) has been released by our emergency response team and supersedes Release 2,” PaperCut said in a September 1 security update.
“You do not need to install previous patches; this patch is an accumulation of all emergency releases. This release addresses two known regressions and adds additional hardening and mitigation against potential attack chains.”
The company issued its first warning on August 27, and in the following days two vulnerabilities – CVE-2026-81578 and CVE-2026-82078 – were disclosed, which could be chained together to achieve remote code execution.
Exploitation had been observed at the time, but according to cyber security firm watchTowr’s head of threat intelligence, Jake Knott, the situation has steadily worsened.
“Last week’s PaperCut saga continues, and has only become ‘less good’ since then,” Knott told Cyber Daily.
“Activity has significantly evolved, and it did so quickly – we are no longer seeing purely exploratory probes to identify vulnerable systems, but real-world exploitation accompanied with hands-on-keyboard interaction from human attackers exploring systems they’ve compromised. If you haven’t picked up on the theme, it’s that this is real.”
Knott also noted that the activity he’s seeing appears to be “above average” in terms of complexity and sophistication, although he does say the bar is admittedly low.
“Attackers are, as always, being selfish – keying access to their deployed in-memory payloads to ensure that only they are able to access compromised hosts and continue further,” Knott said.
“This behaviour is reflective of initial access brokers, and other more aggressive-outcome type operators.
“The message from us (and others) is hopefully very clear. If exposed to the Internet and unpatched at any stage in the last few days, systems should be assumed compromised by an active attacker who is combing through vulnerable hosts looking for interesting or valuable targets.
“And if you haven’t already, now is the time to trigger incident response processes. Patching alone will lock out new attackers while allowing existing attackers to maintain access and go further.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.