Home / Blog / PaperCut releases second emergency patch for exploited flaws
Tech News

PaperCut releases second emergency patch for exploited flaws

PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after.

By Dillip Chowdary • Aug 29, 2026 • Source: BleepingComputer

PaperCut releases second emergency patch for exploited flaws

What happened

PaperCut has issued a second emergency security update after researchers found that the initial fixes for two actively exploited vulnerabilities in its PaperCut NG and MF print management software could be bypassed. The company moved quickly once it became clear that attackers were already exploiting the original flaws in the wild and that the first patch had not fully closed the door.

This article breaks down what the vulnerabilities are, who faces risk, and what administrators running PaperCut NG or MF should verify right now. It is written for IT professionals, security teams, and developers responsible for print infrastructure in organizations that rely on PaperCut's software.

PaperCut discovered that two security vulnerabilities affecting PaperCut NG and MF were being actively exploited before a complete fix was in place. After releasing an initial patch, security researchers identified multiple bypass techniques that rendered the fix insufficient. PaperCut then issued a second emergency update to address those bypass methods. The fact that researchers found more than one way around the original fix suggests the underlying vulnerability surface was broader than the first remediation accounted for, which is not uncommon with complex authentication or input-handling flaws that touch multiple code paths.

How it works

The release of a second emergency patch within a short window is a signal that the vulnerabilities are being taken seriously at the vendor level, but it also means that organizations that applied the first patch cannot assume they are protected. Two separate rounds of emergency patching in response to active exploitation place this in a category that demands immediate attention from any team running affected software, regardless of whether they believed they had already addressed the issue.

PaperCut releases second emergency patch for exploited flaws
Illustration · Pexels

Any organization running PaperCut NG or MF is potentially exposed, particularly those that applied the first patch and have not yet applied the second. PaperCut's print management software is widely deployed in enterprise environments, universities, government agencies, and managed print service providers, which means the blast radius of these vulnerabilities extends across sectors that handle sensitive documents and manage large numbers of networked printers and multifunction devices. Unauthenticated or low-privilege attackers who can reach the PaperCut application server over the network are typically the threat actor profile for this class of vulnerability.

Why it matters

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Organizations that never applied the first patch are at the highest risk because they remain exposed to the original attack vectors as well as any additional methods discovered since. Those that did apply the first patch face a narrower but still real risk from the bypass techniques. Exposure is not limited to internet-facing deployments; internal network access is often sufficient for exploitation, making organizations with flat or poorly segmented networks especially vulnerable even if their PaperCut servers are not directly reachable from the public internet.

Administrators should apply the second emergency patch from PaperCut as the immediate priority. Because multiple bypass methods were confirmed against the first fix, treating that initial patch as sufficient is not appropriate. After applying the update, teams should verify that the patched version is actually running by checking the application's version information through the PaperCut admin console and confirming that no cached or fallback instance of an older version is being served. Organizations should also review access logs for anomalous activity around the application server during the window between the first and second patches, since active exploitation was confirmed during that period.

Network-level controls can serve as a temporary or complementary layer of protection. Restricting access to the PaperCut application server to only the IP ranges and hosts that legitimately need to connect reduces the attack surface regardless of patch status. Any indicators of compromise observed before or after patching should be escalated through standard incident response procedures. PaperCut's security advisories should be monitored for further updates, given the history of bypass discovery in this incident.

Who is affected

The two vulnerabilities affect the core application logic of PaperCut NG and MF, and their exploitation was confirmed in the wild before a complete fix existed. The fact that researchers discovered multiple bypass routes for the original patch suggests the flaws touch more than one code path, likely meaning that the first fix addressed the most obvious exploitation vector without fully accounting for alternative ways to reach the same vulnerable behavior. Print management platforms like PaperCut typically expose web-based administrative interfaces and APIs that handle authentication, job management, and device configuration, any of which can be entry points for this class of vulnerability.

Active exploitation prior to a complete patch being available follows a pattern seen with other widely used enterprise software: threat actors monitor security advisories and proof-of-concept disclosures closely, and they move quickly when a vulnerability in broadly deployed software becomes public. The bypass discoveries compound the issue because organizations following responsible patch timelines may have acted on the first fix in good faith and then been left with a false sense of security while the bypass methods remained usable.

What to watch next

The specific technical details of the two vulnerabilities, including their CVE identifiers, CVSS scores, and exact affected version ranges, have not been specified in the available summary. It is not yet clear from the published information whether the second emergency patch fully resolves all known bypass methods or whether additional research is ongoing that could surface further gaps. The identity and attribution of the threat actors conducting active exploitation has also not been confirmed publicly, which makes it difficult to assess whether the attacks are targeted or opportunistic in nature.

It remains unclear how long the exploitation window existed between the public disclosure of the first patch and the confirmation of bypass techniques, or how many organizations were successfully compromised during that interval. PaperCut has not released details about whether the two flaws are related in root cause or represent separate independent issues within the software. As is common in ongoing security incidents, additional technical analysis from third-party researchers may clarify the full scope in the coming days.

Developer Action Items

  • Inventory whether PaperCut releases second emergency runs in prod, CI, staging, or on laptops before you debate severity.
  • Confirm the vendor's fixed build for PaperCut releases second emergency from BleepingComputer, then schedule the patch window.
  • If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →