What has changed

CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalogue on 31 August. That confirms exploitation in the wild, although CISA records ransomware use as unknown. PaperCut published its initial security bulletin on 27 August and has since issued a second emergency patch with additional hardening.

CVE-2026-81578 is an authentication bypass in the PaperCut NG/MF web management interface. Under specific conditions, unauthenticated remote requests can trigger administrative backend actions before access checks finish. CVE-2026-82078 concerns unsafe dynamic class loading in database utilities. PaperCut and CISA say the flaws can be chained: the first can change configuration, and the second can use manipulated configuration to run Java code already on the application's classpath under the PaperCut server process.

[1][2][3]

Which systems need attention

PaperCut says the bulletin applies to all versions of PaperCut NG and PaperCut MF. Its Emergency Patch Release 2 is available for versions 24, 25 and 26. Customers on version 23 or earlier are told to upgrade to the latest version. This is an emergency patch rather than an ordinary product release, so teams should follow the vendor's upgrade procedure and test printing, authentication and integrations after installation.

The primary Application Server is not the only item to check. PaperCut says Site Servers and secondary or print servers should also be moved to a patched version. Mobility Print, Print Deploy server components, client software, PaperCut Hive and PaperCut Pocket are outside the stated scope. Keep that distinction clear when building the inventory; sharing the PaperCut name does not make every component affected.

[1]

What defenders should do

If a PaperCut NG/MF Application Server is reachable from the public internet, restrict its web interfaces to trusted addresses immediately using firewall or network access controls. PaperCut recommends this even where no suspicious activity has been observed. Treat it as immediate risk reduction while patching proceeds, not as a permanent substitute for updating affected servers.

Identify the version and build of each Application Server, Site Server and secondary server. Preserve current logs and useful security telemetry before disruptive work. Apply Emergency Patch Release 2 to versions 24 through 26, including where the first emergency patch is already installed; upgrade earlier releases to the latest version. PaperCut notes that external database Card/ID lookups and some SAML configurations may need specific post-patch checks, so validate those functions as well as ordinary printing and administration.

Review endpoint, network and PaperCut server logs for unexpected activity involving the Application Server, missing or truncated server logs, unusual configuration changes and unexpected child processes. The vendor warns that observed artefacts may be removed, so their absence does not establish that a server is safe. If compromise is suspected, activate the incident response plan, secure existing backups and follow PaperCut's rebuild-from-clean-backup guidance rather than assuming the patch removes an existing intrusion.

  • Restrict public web access to trusted addresses immediately.
  • Inventory Application, Site and secondary servers with their exact versions and builds.
  • Preserve relevant logs before patching or rebuilding.
  • Install Emergency Patch Release 2 on versions 24 to 26, or upgrade older versions.
  • Verify printing, SAML, Card/ID lookup and server health after maintenance.
[1][2][3]

The Beekeeper view

Print management servers are easy to classify as background infrastructure, but they combine web administration, directory integration and broad internal reach. That makes ownership and exposure data as important as the patch itself.

The durable control is a service register that records every management server, its external routes, current build, named owner and recovery method. Pair it with tested restrictions on administrative interfaces. That will not eliminate vulnerability risk, but it shortens the gap between a verified exploitation warning and a complete, accountable response.

[1][2][3]
Restrict public access to PaperCut NG/MF immediately, identify every application and site server, then apply PaperCut's Emergency Patch Release 2 or upgrade older installations to the latest version.

Primary sources

  1. PaperCut NG/MF Security Bulletin (27 August 2026) — PaperCut, 27 August 2026
  2. Known Exploited Vulnerabilities Catalog: CVE-2026-81578 — US Cybersecurity and Infrastructure Security Agency, 31 August 2026
  3. Known Exploited Vulnerabilities Catalog: CVE-2026-82078 — US Cybersecurity and Infrastructure Security Agency, 31 August 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.