PaperCut Vulnerability Chain Forces Vendor to Ship Two Emergency Patches

by Rebecca Sutton

A PaperCut vulnerability chain has let hackers slip past login screens on print management servers. Once inside, they can run their own code. PaperCut disclosed the flaw on 27 August. It confirmed attacks were already under way and told every PaperCut NG and PaperCut MF customer to patch right away. The vendor has already needed two emergency patches to close the gap.

Business team reviewing printed reports at a desk after a PaperCut vulnerability disrupted print servers

The affected software sits in a lot of ordinary places. Hospitals, councils, universities and mid-sized businesses all use PaperCut. It manages print jobs, tracks costs and controls who can print what. That everyday role is exactly why the flaw matters. A print server rarely gets the same scrutiny as a firewall or a domain controller. So it can sit exposed to the internet for years without anyone noticing.

How the PaperCut vulnerability works

Researchers found two separate bugs that work together. The first is tracked as CVE-2026-81578 and rated 8.8 out of 10. It lets a hacker skip the login check on PaperCut’s web interface. They send a request in an odd format. That request triggers admin tools before the software finishes checking who is allowed in.

Once inside, the attacker edits a few settings to reach the second flaw. That one is CVE-2026-82078, rated a more severe 9.4. It lives in how PaperCut loads database drivers. The app loads whatever driver a setting names, without checking it against an approved list. Point that setting at a bad database link, and PaperCut will run any code the attacker wants on the server.

Security firm Huntress first spotted attacks on two of its own customers. Another security firm then worked out how the two bugs could be chained together. Between them, the pair turns a login bypass into full remote code execution. No password needed.

Two patches in two days

PaperCut’s first emergency patch went out within a day of the warning. Researchers quickly found ways round it, though. A second, more thorough patch followed on 28 August. It covers versions 24, 25 and 26, across Windows, Linux and macOS. PaperCut is now telling customers to install the second release even if they already applied the first. The initial fix left gaps a determined attacker could still exploit. Anyone still running version 23 or older has been told to upgrade rather than wait for a patch that may never arrive.

PaperCut says the attacks seen so far look limited and targeted, not a mass sweep. The firm also says it does not yet know what the hackers wanted. Researchers have found hackers running basic commands to look around. They list files and running programs, then delete log files to cover their tracks.

Why this feels familiar

PaperCut has been here before. A 2023 flaw in the same product line, CVE-2023-27350, was picked up by ransomware gangs within weeks. They used it to push ransomware onto victim networks. That history is part of why security teams are treating this new PaperCut vulnerability so seriously. Print management software has a track record of turning into a ransomware entry point once hackers work out how to abuse it at scale.

Businesses that treat a print server as low risk are missing the point. Any server with database access is worth an attacker’s time, whatever it happens to print for a living. A print queue tool, a helpdesk portal or a backup console can all give an attacker the same way in. Once they are in, the goal is rarely the print jobs themselves.

What makes this PaperCut vulnerability notable is not just the severity score. Two flaws that might each look minor on their own add up to something far worse once combined. That combination is precisely what a routine vulnerability scan is least likely to catch.

What to do now

If your business runs PaperCut NG or PaperCut MF, the priority is simple. Apply the second emergency patch, not just the first. Take the server off the public internet if it can be reached there. Restrict access to trusted IP ranges or a VPN for now. Check server logs for the signs PaperCut has published, like missing log files or database driver errors. Those can point to an attack that already happened.

None of this needs special tools. It needs knowing which of your systems run PaperCut in the first place, and that is often the harder part. A basic list of your systems would have flagged this server the moment the warning went out. Without one, teams are left hoping someone remembers where the print software actually lives.

Smaller IT teams should not assume this only hits large firms. PaperCut is popular precisely because it is cheap and easy to set up. That means plenty of the exposed copies researchers are finding sit at small businesses with no security team watching for advisories like this one.

Once the immediate patching is done, ask a broader question. How would your team have found out about this PaperCut vulnerability if the vendor had stayed quiet for another week? Relying only on the vendor to speak up means you learn about an active attack only when it decides to tell you. That is often later than most firms would like.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like