Urgent PaperCut NG/MF Vulnerability: What You Need to Know

Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today.

In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. Every supported version of both products is considered potentially exposed; an emergency patch is now available for v24, v25, and v26, and PaperCut's investigation is still underway. Full details are in PaperCut's official bulletin, Urgent Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026), and we'll keep this post updated as new information comes in.

Publish and update history

Published at 9:10 AM CT on August 28, 2026.

Updated at 7:10 CT on September 1, 2026, to add known post-patch issues with Card/ID lookups and SAML and Emergency Patch (Release 3).

What's happening, at a glance

Here's what PaperCut has confirmed so far:

  • Its security team is investigating active exploitation of a vulnerability in PaperCut NG and PaperCut MF, and has confirmed multiple customer incidents.
  • All versions of NG and MF are listed as potentially impacted, so your specific version number alone doesn't tell you whether you're exposed.
  • An initial emergency patch was released for NG/MF versions 25 and 26. An updated Emergency Patch (Release 2) was released for versions 24, 25, and 26. 
  • PaperCut released an updated Emergency Patch (Release 3) that includes additional hardening beyond the original emergency patch and the emergency patch (Release 2). The Release 3 patch includes versions 24, 25, and 26. We recommend all customers install Release 3, even if you have already applied the first two emergency patches.
  • Two CVEs have been published. CVE-2026-82078 (9.4, Critical) — unsafe dynamic class loading in the database connector, allowing arbitrary code execution. CVE-2026-81578 (8.8, High) — an authentication bypass in the web management interface. 
  • PaperCut is updating its bulletin as the investigation continues, so treat this as a developing situation.

First: check whether your PaperCut server is exposed to the internet

Before anything else, find out whether your PaperCut NG/MF Application Server can be reached from the public internet. If it can, restrict access immediately.

Use firewall rules, network access controls, or an equivalent measure so the server's web interfaces are reachable only from trusted IP addresses, such as your internal network. PaperCut recommends this step even if you haven't seen anything suspicious yet.

It's the single most effective thing you can do while the investigation continues.

PaperCut has released an emergency patch

A call center team solving a business phone system issue.

PaperCut published emergency, out-of-cycle builds for PaperCut MF and PaperCut NG versions 25 and 26, covering Windows, Linux, and macOS. 

Following further work with its internal security team and external researchers, including Huntress and watchTowr, PaperCut released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch.

The patch is specifically intended for customers with public-facing PaperCut servers who are unable to mitigate the issue another way. This is a rarely used feature, but if you use Card/ID number lookups from an external database, you'll need to add a configuration key (security.card-number-lookup.enabled=Y) to server/security.properties and restart the Application Server after installing — otherwise PaperCut will silently ignore those lookup calls. Review PaperCut's FAQ for the full steps before you install.

One thing to check: PaperCut's patch guidance covers more than the primary Application Server. If you use Site Servers or secondary print servers, those need to be updated to a patched version too, not just your main server. Print Deploy and Mobility Print aren't affected and don't need updates.

A few customers have reported that Card/ID number lookups and SAML stopped working correctly after installing the patch. PaperCut is investigating. If you use SQL Server for external card lookups with the older Sourceforge jTDS driver, PaperCut recommends updating to the current Microsoft SQL JDBC driver as a first step. If you're still seeing issues after that, contact your reseller or PaperCut Support directly.

If you're running an older PaperCut version, don't assume you're in the clear. PaperCut currently lists all versions of NG and MF as potentially impacted.

Indicators of compromise

PaperCut has shared a few early indicators of compromise. In your server.log, watch for:

  • Alerts from your intrusion-detection, endpoint-security, or network-monitoring tools referencing the PaperCut Application Server, particularly unusual activity from pc-app.exe
  • Missing, unexpectedly truncated, or deleted PaperCut server.log files.
  • Any of the following entries in server.log:
    • ERROR No suitable driver found for jdbc:no:x
    • ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Not seeing any of these signs isn't confirmation that you're in the clear. PaperCut's investigation is ongoing, and it expects to publish more specific, validated indicators as they're confirmed.

The bottom line

This is an active security issue, not a theoretical one.

If you use PaperCut NG or MF:

  1. Find out whether your Application Server is exposed to the internet.
  2. Restrict public access immediately if it is.
  3. Review PaperCut's emergency patch and apply it where appropriate.
  4. Check your logs and security tools for suspicious activity.
  5. Keep watching PaperCut's advisory as new information is released.

Marco is continuing to monitor the situation. If you're a Marco client and need help reviewing your PaperCut environment or determining your next step, contact Marco. Marco also recommends that our clients sign up to subscribe to PaperCut security notifications, so they are alerted immediately to any future updates/vulnerabilities.

Resources

PaperCut: Urgent Security Advisory — PaperCut NG/MF Security Bulletin, August 27, 2026

PaperCut Security Notifications: https://www.papercut.com/contact/security/

 

Related Posts

How To Choose the Best Wide Format Printer for Your Business
How To Choose the Best Wide Format Printer for Your Business

If you're printing large-format jobs often enough that outsourcing is starting to feel expensive, slow, or both, you might be wondering if it’s time to bring a wide format printer ...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

How Do Thermal Printers Work? Everything You Need To Know Before You Buy
How Do Thermal Printers Work? Everything You Need To Know Before You Buy

Ever tried to scan the barcode on a shipping label only for it to come back illegible? Or watched your receipt printer jam for the third time today while customers wait in line? We...

Compatible Toner Cartridge vs. Original: The Real Impact on Your Printers
Compatible Toner Cartridge vs. Original: The Real Impact on Your Printers

When it comes to toner, you have choices: Do you purchase the Original Equipment Manufacturer (OEM) toner, or go with a cheaper, but allegedly “compatible” toner? Depending on the ...

What Is Cloud Printing?
What Is Cloud Printing?

Cloud printing is a technology that lets users send print jobs from any internet-connected device — a laptop, smartphone, or tablet — to a printer without being physically on the s...

Office Copiers Explained: How They Work and What They Can Do in 2026
Office Copiers Explained: How They Work and What They Can Do in 2026

Modern copy machines have evolved far beyond simple copying. They're now sophisticated multifunction devices that can significantly impact your office's productivity and efficiency...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...