Patching on day one used to be the good outcome. For PaperCut customers this week, day one wasn’t enough, because the first patch didn’t actually close the hole.
The vulnerability chain
PaperCut NG/MF, the print management software widely deployed across schools, universities, public-sector offices and enterprises to control and audit printing, carries two flaws that combine into pre-authentication remote code execution. CVE-2026-81578, rated 8.8, is an improper access control weakness in the web management interface that lets unauthenticated requests reach administrative functions before the server finishes checking access. CVE-2026-82078, rated 9.4, is an unsafe dynamic class-loading flaw in the product’s database connection utilities. Chained together, an attacker with no credentials at all can reach code execution on an internet-facing PaperCut server.
The timeline that should concern you
Huntress observed the first exploitation attempts on August 26, before PaperCut had published anything. The vendor issued a security bulletin on August 27 and shipped an emergency patch for NG/MF versions 25 and 26 the same day. Then watchTowr’s research team, working directly with PaperCut, found multiple ways to bypass that first patch and an additional authentication bypass on top of it. PaperCut shipped a second emergency patch on August 28, this time extending coverage to version 24 as well. The gap between “patched” and “actually protected” was roughly 24 hours, and anyone who patched once on the 27th and moved on is still exposed.
Why this matters beyond PaperCut
This is the pattern that catches organisations out again and again: a vendor ships a fix under pressure, security researchers immediately test it against real exploitation techniques, and the fix turns out to be incomplete. If your patch management process treats “patched” as a checkbox rather than a state to re-verify, a bypassed emergency patch sails straight past you. PaperCut’s install base skews heavily toward education and public-sector environments across Europe, exactly the kind of organisation running lean IT teams that patch once, log it, and move to the next ticket.
What to do now
If you run PaperCut NG/MF, confirm you’re on the second emergency patch, not the first, released August 28, and covering versions 24, 25 and 26. Check your web management interface isn’t unnecessarily exposed to the internet regardless of patch level, since defence in depth is what catches the next bypass nobody’s found yet. And build a habit of treating emergency patches for actively exploited vulnerabilities as provisional until independent researchers have had a few days to hammer on them.
If you need your print infrastructure, patch management process, or exposure to actively exploited software audited, contact Excello Digital. We help European organisations verify that “patched” actually means protected.
