← Home
CYBERSECURITY

PaperCut Issues Second Emergency Patch for Actively Exploited Print Software Flaws

September 4, 2026 Daniel Cross

Why the First Patch Failed to Stop Attacks

PaperCut has issued a second emergency security update for two critical vulnerabilities in its PaperCut NG and MF print management platforms after researchers found ways to circumvent the initial fixes released earlier this month. The vulnerabilities, which allow unauthenticated remote code execution, were being actively exploited in the wild, prompting the company to accelerate its patching efforts. The update addresses flaws identified as CVE-2026- and CVE-2026- , which could let attackers gain full control of affected servers without user interaction.

The initial security update, released on August 15, attempted to mitigate the vulnerabilities by restricting access to certain administrative endpoints. However, security researchers from Project Zero and independent teams demonstrated that attackers could still exploit the flaws using alternative request headers and encoded payloads that evaded the original filters. PaperCut acknowledged that the bypass techniques relied on subtle inconsistencies in how the software parsed HTTP requests, particularly in legacy authentication modules that were not fully covered by the first fix. The company stated that the second patch includes deeper input validation and improved logging to detect evasion attempts.

How Are Organizations Responding to the Ongoing Threat?

Many enterprises using PaperCut NG and MF in hybrid work environments have been urged to apply the update immediately, especially those with internet-facing print servers. Cybersecurity agencies including CISA and the UK’s NCSC have issued alerts highlighting the ongoing exploitation attempts, noting that threat actors are using the vulnerabilities to deploy ransomware and establish persistent backdoors. PaperCut emphasized that while no data theft has been confirmed in reported cases, the potential for lateral movement within networks remains high. The company has also provided a temporary mitigation guide for organizations unable to patch immediately, involving network segmentation and disabling remote print administration.

What versions of PaperCut are affected by these vulnerabilities? PaperCut NG and MF versions prior to 22.0.11 and 22.1.5 are vulnerable, with the emergency update applying to all supported releases in the 22.x series.

Frequently Asked Questions

Is there evidence that customer data has been stolen in these attacks? PaperCut has stated there is no confirmed evidence of data exfiltration linked to these specific exploits, though attackers have used the access to deploy malware and conduct reconnaissance.

Can the vulnerabilities be exploited if the print server is not exposed to the internet? While internet exposure significantly increases risk, the vulnerabilities could still be exploited internally if an attacker gains foothold on the network, making internal segmentation and patching critical.

Read full article on Tech Site News →