PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation.
The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.
The vendor issued a security bulletin on August 27 and released the first emergency patch the next day for PaperCut NG/MF versions 25 and 26. The second emergency patch was released later the same day to deliver additional hardening, including for version 24. Indicators of compromise (IoCs) have also been made available.
It was initially believed that attackers had exploited a single vulnerability, but PaperCut and the security firms monitoring the situation, Huntress and WatchTowr, revealed that two zero-days have been exploited.
One of them is tracked as CVE-2026-81578 and described as a high-severity authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations.












