PaperCut confirmed on 27 August that its own response team was investigating active exploitation of PaperCut NG and PaperCut MF, and that it knew of confirmed customer incidents 1. PaperCut is an Australian software vendor whose print management servers sit between office staff and the printers they send jobs to, which in most estates means a server every desktop in the building is configured to talk to.
The chain joins CVE-2026-81578, an authentication bypass scoring 8.8, to CVE-2026-82078, unsafe dynamic class loading scoring 9.4. A CVE, short for Common Vulnerabilities and Exposures, is the industry's shared reference number for a single flaw. The bypass carries an attacker who has never logged in as far as a configuration change, and the configuration change gets the print server to load and run Java bytecode of the attacker's choosing. Huntress, an American managed detection and response firm, reproduced the whole pre-authentication chain on a stock PaperCut NG 25.0.11.75758 server and found it running in two customer environments 2.
Emergency Patch Release 3 landed on 1 September, the third fix in six days, so an organisation that acted on the first bulletin has taken the print estate down three times inside a working week. Exploitation running ahead of a vendor's own fix has form on this beat: Check Point's remote access VPN carried an authentication bypass for roughly a month before June's hotfix reached customers .
NHS England issued its own alert on the flaws for UK health organisations 3, which is the pattern that decides who actually patches. A vendor bulletin reaches customers on a mailing list; a health service alert reaches every trust that has to answer for it.
