Urgent PaperCut NG/MF Vulnerability: What You Need to Know

By: Marco
August 28, 2026

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today.

In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. Every supported version of both products is considered potentially exposed; an emergency patch is now available for v24, v25, and v26, and PaperCut's investigation is still underway. Full details are in PaperCut's official bulletin, Urgent Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026), and we'll keep this post updated as new information comes in.

Publish and update history

Published at 9:10 AM CT on August 28, 2026.

What's happening, at a glance

Here's what PaperCut has confirmed so far:

  • Its security team is investigating active exploitation of a vulnerability in PaperCut NG and PaperCut MF, and has confirmed multiple customer incidents.
  • All versions of NG and MF are listed as potentially impacted, so your specific version number alone doesn't tell you whether you're exposed.
  • An initial emergency patch was released for NG/MF versions 25 and 26. 
  • PaperCut released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. The Release 2 patch includes versions 24, 25, and 26. We recommend all customers install Release 2, even if you have already applied the original emergency patch.
  • Two CVEs have been published. CVE-2026-82078 (9.4, Critical) — unsafe dynamic class loading in the database connector, allowing arbitrary code execution. CVE-2026-81578 (8.8, High) — an authentication bypass in the web management interface. 
  • PaperCut is updating its bulletin as the investigation continues, so treat this as a developing situation.

First: check whether your PaperCut server is exposed to the internet

Before anything else, find out whether your PaperCut NG/MF Application Server can be reached from the public internet. If it can, restrict access immediately.

Use firewall rules, network access controls, or an equivalent measure so the server's web interfaces are reachable only from trusted IP addresses, such as your internal network. PaperCut recommends this step even if you haven't seen anything suspicious yet.

It's the single most effective thing you can do while the investigation continues.

PaperCut has released an emergency patch

A call center team solving a business phone system issue.

PaperCut published emergency, out-of-cycle builds for PaperCut MF and PaperCut NG versions 25 and 26, covering Windows, Linux, and macOS. 

Following further work with its internal security team and external researchers, including Huntress and watchTowr, PaperCut released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch.

The patch is specifically intended for customers with public-facing PaperCut servers who are unable to mitigate the issue another way. This is a rarely used feature, but if you use Card/ID number lookups from an external database, you'll need to add a configuration key (security.card-number-lookup.enabled=Y) to server/security.properties and restart the Application Server after installing — otherwise PaperCut will silently ignore those lookup calls. Review PaperCut's FAQ for the full steps before you install.

One thing to check: PaperCut's patch guidance covers more than the primary Application Server. If you use Site Servers or secondary print servers, those need to be updated to a patched version too, not just your main server. Print Deploy and Mobility Print aren't affected and don't need updates.

If you're running an older PaperCut version, don't assume you're in the clear. PaperCut currently lists all versions of NG and MF as potentially impacted.

What to watch for in your environment

PaperCut has shared a few early indicators of compromise. In your server.log, watch for:

  • Alerts from your intrusion-detection, endpoint-security, or network-monitoring tools referencing the PaperCut Application Server, particularly unusual activity from pc-app.exe
  • Server.log files that are missing, deleted, or unexpectedly short
  • The specific entries "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST."

Not seeing any of these signs isn't confirmation that you're in the clear. PaperCut's investigation is ongoing, and it expects to publish more specific, validated indicators as they're confirmed.

The bottom line

This is an active security issue, not a theoretical one.

If you use PaperCut NG or MF:

  1. Find out whether your Application Server is exposed to the internet.
  2. Restrict public access immediately if it is.
  3. Review PaperCut's emergency patch and apply it where appropriate.
  4. Check your logs and security tools for suspicious activity.
  5. Keep watching PaperCut's advisory as new information is released.

Marco is continuing to monitor the situation. If you're a Marco client and need help reviewing your PaperCut environment or determining your next step, contact Marco.

Resources

PaperCut: Urgent Security Advisory — PaperCut NG/MF Security Bulletin, August 27, 2026

 

Topics: Security, Copiers & Printers