PaperCut Issues Second Patch as Bypasses Found
PaperCut's first emergency patch had bypasses. CVE-2026-81578 (auth bypass, CVSS 8.8) and CVE-2026-82078 (RCE, CVSS 9.4) remain exploitable on EP1 installs. Apply Emergency Patch Release 2.

PaperCut has released Emergency Patch Release 2 for PaperCut NG and MF after security researchers at Huntress and watchTowr confirmed multiple bypass methods in the original fix. If you applied the first emergency patch, you are still vulnerable. Emergency Patch Release 2 is the required update.
Two CVEs are in play. CVE-2026-82078 is the more critical flaw, rated CVSS 9.4: it allows an attacker to execute arbitrary Java bytecode by exploiting how PaperCut loads database driver classes without an approved allowlist. CVE-2026-81578, rated CVSS 8.8, is the authentication bypass that makes the RCE path accessible without credentials. Researchers confirmed both remain exploitable on Emergency Patch Release 1 installs via alternate request paths. Per Rapid7’s technical analysis, the attack chain is reproducible against the initial patch.
What to patch
Emergency Patch Release 2 covers PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS. Version 23 and older are out of active support; PaperCut’s guidance is to upgrade to a supported release rather than apply an emergency patch. Patch download links and version-specific instructions are in PaperCut’s updated security bulletin.
The EP2 release includes “additional hardening beyond the original emergency patch,” per PaperCut’s statement, following coordinated disclosure from Huntress and watchTowr.
If you cannot patch immediately
The IP-restriction mitigation from the original advisory still applies as a temporary measure: restrict the PaperCut web management interface to trusted internal IP ranges via firewall rules. Limit this to as narrow a set as your environment allows. This reduces exposure but does not close the vulnerability; a user on an authorized IP can still trigger CVE-2026-82078 through an authenticated path, so “restricted access” means tightly controlled, not just “off the public internet.”
Priority call
Apply Emergency Patch Release 2 before anything else competing for this week’s maintenance window. PaperCut NG and MF are deployed broadly across enterprise, government, and education environments, often with broad internal network access. Active exploitation was confirmed before the first patch shipped. The bypass window is open.
Previously: PaperCut NG/MF Zero-Day Under Active Attack covers the original advisory, initial mitigation steps, and detection signals.
- [ HIGH ]CVE-2026-81578PaperCut NG/MF Authentication Bypass
- [ CRITICAL ]CVE-2026-82078PaperCut NG/MF Unsafe Class-Loading RCE
Found this useful? Share it.


