PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency patch to address CVE-2026-82078 and CVE-2026-81578. These zero-day vulnerabilities enable attackers to bypass authentication and execute remote code. Threat actors are currently utilizing these flaws for data theft and hands-on-keyboard activity, which includes installing legitimate remote access software on servers exposed to the internet. The U.S. Cybersecurity and Infrastructure Security Agency has listed these vulnerabilities in its Known Exploited Vulnerabilities catalog. A Metasploit Framework module created by Stephen Fewer has made the exploit chain more accessible to attackers.
What changed
No new developments regarding PaperCut vulnerabilities were reported in the latest source material.
Live updates
-
PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency patch to address CVE-2026-82078 and CVE-2026-81578. These zero-day vulnerabilities enable attackers to bypass authentication and execute remote code. Threat actors are currently utilizing these flaws for data theft and hands-on-keyboard activity, which includes installing legitimate remote access software on servers exposed to the internet. The U.S. Cybersecurity and Infrastructure Security Agency has listed these vulnerabilities in its Known Exploited Vulnerabilities catalog. A Metasploit Framework module created by Stephen Fewer has made the exploit chain more accessible to attackers.
Why it matters
The vulnerabilities allow unauthorized remote access to server environments. This increases the risk of persistent network intrusion and sensitive data exfiltration. The availability of public exploit modules accelerates the pace of potential attacks.
What is confirmed
- PaperCut issued a second emergency patch for CVE-2026-82078 and CVE-2026-81578.
- The flaws allow attackers to bypass authentication and execute remote code.
- The U.S. Cybersecurity and Infrastructure Security Agency added these flaws to its Known Exploited Vulnerabilities catalog.
- Stephen Fewer submitted a Metasploit Framework module that increases accessibility of the exploit chain.
Still unconfirmed
- Hackers are using these vulnerabilities for data theft and installing remote access software on internet-facing servers.
What to watch next
- Reports of successful exploitation following the second patch
- Updates on the number of affected organizations
- Further additions to the Metasploit Framework regarding these CVEs
confidence 100%Sources used for this update (4)
- www.securityweek.com — Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
- www.bleepingcomputer.com — HPE patches critical ArubaOS-CX remote code execution flaw
- www.bleepingcomputer.com — Plex warns users to patch security vulnerabilities immediately
- thecyberexpress.com — SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
-
PaperCut releases second patch as hackers deploy remote access tools
PaperCut has issued a second emergency patch for vulnerabilities CVE-2026-82078 and CVE-2026-81578. These zero-day flaws allow attackers to bypass authentication and execute remote code. Hackers are now using these vulnerabilities for data theft and hands-on-keyboard activity, including the covert installation of legitimate remote access software on internet-facing servers. The U.S. Cybersecurity and Infrastructure Security Agency has added these flaws to its Known Exploited Vulnerabilities catalog. A new Metasploit Framework module submitted by Stephen Fewer further increases the accessibility of this exploit chain for attackers.
Why it matters
The vulnerabilities affect PaperCut NG and MF print management software. The company previously faced a wave of attacks in 2023 that targeted higher education customers. Current exploitation involves chaining two separate flaws to gain unauthorized server access.
What is confirmed
- PaperCut released a second emergency patch for vulnerabilities CVE-2026-82078 and CVE-2026-81578.
- The vulnerabilities allow for authentication bypass and remote code execution.
- CISA added the PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog.
- Attackers are using these flaws to perform data theft and hands-on-keyboard activity.
Still unconfirmed
- Threat actors are installing legitimate remote access software on compromised internet-facing PaperCut Application Servers.
- Stephen Fewer submitted pull request #21842 to the Metasploit Framework to make the zero-day chain more accessible.
What to watch next
- Updated patching rates for the 47% of installations previously reported as vulnerable.
- Reports of specific data sets stolen during the active intrusions.
confidence 90%Sources used for this update (10)
- www.macworld.com — iOS 27 beta 4 is out now with further refinements and fixes
- www.securityweek.com — More Details Emerge on Exploited PaperCut Vulnerabilities
- www.cybersecuritydive.com — PaperCut issues emergency patches as threat actors target chained vulnerabilities
- cyberpress.org — Metasploit Exploit Targets Actively Exploited PaperCut NG/MF Zero-Day RCE Chain
- dailytechnewsshow.com — The EU Regulates ChatGPT Like a Search Engine – DTNS 5343
- www.helpnetsecurity.com — Attackers plant remote access tools on compromised PaperCut servers
- securityaffairs.com — U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
- www.securityweek.com — PaperCut Exploitation Escalates to Active Intrusions
- www.bleepingcomputer.com — Recently patched PaperCut zero-days used in data theft attacks
- www.securityweek.com — WatchGuard Patches Critical Vulnerabilities
-
PaperCut Issues Second Emergency Patch for Exploited Vulnerabilities
PaperCut released a second emergency patch to address security flaws that allow attackers to execute code without authentication. These vulnerabilities, categorized as critical and high, are under active exploitation by hackers targeting PaperCut servers. Despite the availability of fixes, 47% of tracked installations remain unpatched and vulnerable to remote code execution. The attack involves chaining two separate flaws to gain unauthorized access, prompting urgent warnings for administrators to update their systems immediately to prevent server compromise.
Why it matters
PaperCut software manages print services across many corporate networks. Remote code execution allows external actors to take full control of a server. This vulnerability is particularly dangerous because it does not require valid user credentials.
What is confirmed
- PaperCut released a second emergency patch for exploited flaws.
- Attackers are chaining two PaperCut flaws to execute code without authentication.
- PaperCut servers are under active attack.
Still unconfirmed
- 47% of tracked installations still run unpatched versions vulnerable to RCE.
- The vulnerabilities are categorized as critical and high.
What to watch next
- Reports of successful breaches resulting from the chained flaws
- Confirmation of the total number of compromised servers
- Further patches addressing remaining high-risk vulnerabilities
confidence 80%Sources used for this update (6)
- The Hacker News — Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
- SecurityWeek — PaperCut Releases Emergency Patch for Exploited Zero-Day
- Printweek — PaperCut targeted by hackers
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws
- CCB Belgium — Warning: Critical and High vulnerability in PaperCut, Patch Immediately!
- securityaffairs.com — Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch