logo

PaperCut releases second emergency patch for exploited flaws

ID: 4745f4c2-c433-58e2-94cc-f041279d0914

STIX ID: report--4745f4c2-c433-58e2-94cc-f041279d0914

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: Lawrence Abrams

...
...

PaperCut released Emergency Patch Release 2 for PaperCut NG/MF to address two actively exploited vulnerabilities — CVE-2026-81578 (high-severity authentication bypass) and CVE-2026-82078 (critical unsafe dynamic class-loading enabling remote code execution) — after researchers reproduced the issues, found multiple patch bypasses and an additional bypass; customers are urged to install the updated patch, restrict access to web interfaces, monitor for specified log errors and pc-app.exe post‑exploit activity, and upgrade older versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.