Skip to content
feed: live
>_0dayNews
threat intel

PaperCut Issues Second Patch as Bypasses Found

PaperCut's first emergency patch had bypasses. CVE-2026-81578 (auth bypass, CVSS 8.8) and CVE-2026-82078 (RCE, CVSS 9.4) remain exploitable on EP1 installs. Apply Emergency Patch Release 2.

PaperCut Issues Second Patch as Bypasses Found
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

PaperCut has released Emergency Patch Release 2 for PaperCut NG and MF after security researchers at Huntress and watchTowr confirmed multiple bypass methods in the original fix. If you applied the first emergency patch, you are still vulnerable. Emergency Patch Release 2 is the required update.

Two CVEs are in play. CVE-2026-82078 is the more critical flaw, rated CVSS 9.4: it allows an attacker to execute arbitrary Java bytecode by exploiting how PaperCut loads database driver classes without an approved allowlist. CVE-2026-81578, rated CVSS 8.8, is the authentication bypass that makes the RCE path accessible without credentials. Researchers confirmed both remain exploitable on Emergency Patch Release 1 installs via alternate request paths. Per Rapid7’s technical analysis, the attack chain is reproducible against the initial patch.

What to patch

Emergency Patch Release 2 covers PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Version 23 and older are out of active support; PaperCut’s guidance is to upgrade to a supported release rather than apply an emergency patch. Patch download links and version-specific instructions are in PaperCut’s updated security bulletin.

The EP2 release includes “additional hardening beyond the original emergency patch,” per PaperCut’s statement, following coordinated disclosure from Huntress and watchTowr.

If you cannot patch immediately

The IP-restriction mitigation from the original advisory still applies as a temporary measure: restrict the PaperCut web management interface to trusted internal IP ranges via firewall rules. Limit this to as narrow a set as your environment allows. This reduces exposure but does not close the vulnerability; a user on an authorized IP can still trigger CVE-2026-82078 through an authenticated path, so “restricted access” means tightly controlled, not just “off the public internet.”

Priority call

Apply Emergency Patch Release 2 before anything else competing for this week’s maintenance window. PaperCut NG and MF are deployed broadly across enterprise, government, and education environments, often with broad internal network access. Active exploitation was confirmed before the first patch shipped. The bypass window is open.


Previously: PaperCut NG/MF Zero-Day Under Active Attack covers the original advisory, initial mitigation steps, and detection signals.

Related CVEs

Found this useful? Share it.