PaperCut Software published an urgent security bulletin on 27 August 2026, Australian Eastern Standard Time. The objects are PaperCut NG and PaperCut MF. The company said its security response team is investigating active exploitation, that it is aware of confirmed customer incidents, and that the investigation is ongoing. The news is the vendor page, not a break-in.

Immediate action on that page is a network sentence, not a payload. If the Application Server’s web interfaces are reachable from the public internet, restrict them to trusted addresses now. Firewall, network access control, equivalent. Take that step even if you have not seen anything odd. Then look at the emergency patch.

Primary is PaperCut’s own bulletin: “URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026),” last updated 30 August 2026. The vulnerability log on papercut.com points at the same date and two CVE identifiers. Huntress and watchTowr are named on the vendor page as external researchers who helped harden Release 2. Huntress also published its own customer note on 27 August, with a 28 August afternoon Eastern update. The calendar on this page follows PaperCut’s timestamps in AEST. Huntress is a second dated clip, not a recipe book.

PaperCut shipped Emergency Patch Release 2 for NG and MF
Original illustration, The Standard art desk (Pablo Picasso). Not a photograph of a real event.Download

The bulletin’s timeline, as PaperCut printed it, is the spine. 27 August: initial bulletin. 27 August 8:00 p.m. AEST: minor wording. 27 August 9:02 p.m.: investigation update. 28 August 2:10 a.m. AEST: emergency patch for v25 and v26. 28 August 10:43 a.m.: card and ID lookup note. 28 August 8:42 p.m. AEST: Emergency Patch Release 2, additional hardening, thanks to Huntress and watchTowr, plus a security.properties note for a rarely used external card-lookup feature. 28 August 10:08 p.m.: Release 2 for v24. 29 August: FAQs, then a note that some sites saw card lookup and SAML trouble after the patch. 30 August 10:34 a.m. AEST: official release still in progress, support at support.papercut.com, more card-lookup advice. 30 August 3:35 p.m. AEST: more investigation leads added to the bulletin.

Those leads stay on PaperCut’s page for administrators who already run the product. Follow the vendor bulletin. This newspaper is not a substitute for it. The file is names, dates, CVEs, who should patch, and what the vendor says to restrict. Not a chain. Not a class-loading walkthrough. Not a request to paste.

Bulletin
A printed urgent security bulletin on a dark print-room desk beside a small application server, no people.

Two CVEs are now public on that page. CVE-2026-82078 is unsafe dynamic class loading in the database connector, CWE-470, CVSS 9.4 Critical on the vector PaperCut printed. Mitigated in Emergency Patch Release 2. CVE-2026-81578 is an authentication bypass in the web management interface, CWE-306, CVSS 8.8 High, unauthenticated remote requests that can modify certain system configurations under specific conditions. Also mitigated in Release 2. Those are PaperCut’s sentences. This page will not unpack “specific conditions” into a lab.

Who is in scope: all versions of PaperCut NG and PaperCut MF, the vendor said. Site servers and secondary print servers should be updated to a patched build, not only the primary Application Server. Print Deploy and Mobility Print are not affected. Mobility Print ports can stay as they are, per the FAQ. Versions before v24: the recommended path is to upgrade to the latest, not to wait for a 23-and-older emergency branch. PaperCut was explicit that this emergency patch is not an official release. Usual process did not run. It is for public-facing servers that cannot take other mitigating action yet. An official release is still being built as of 30 August 10:34 a.m. AEST.

Release 2 is the build this file wants on the page. PaperCut recommends it even if you already installed the first emergency patch. Checksums in SHA256 are on the vendor table for Windows, Linux, and macOS, for MF and NG, for v24, v25, and v26. Print that the table exists. Do not turn this article into a download mirror. Get the bits from PaperCut. Follow the standard upgrade procedure PaperCut already documents.

A rarely used feature got a properties flag. External database Card/ID number lookups default off after the patch unless you set security.card-number-lookup.enabled=Y in server/security.properties and restart. Most customers will not need that key. If you use SQL Server for those lookups with the old Sourceforge jTDS driver, PaperCut’s 30 August FAQ says move to the current Microsoft SQL JDBC driver as a first step. SAML and card lookup reports after the patch are under investigation as of 29–30 August. That is a post-patch support story, not a reason to skip Release 2 if you are on the public internet.

Huntress, 27 August, said it had seen two customer environments, that observed activity looked like discovery, and that it had not seen secondary malware in those recoveries as of that post. A 28 August 2:45 p.m. ET update on that post said PaperCut had shipped Release 2 and assigned the two CVEs. Huntress also wrote that it reproduced a chain in a lab. This newspaper is not reproducing it. This newspaper is not hosting a proof of concept. Confirmed incidents plus a vendor patch is the news. A lab recreation is a researcher’s note. Keep it off the how-to shelf.

Patch crate
A sealed emergency-patch crate labelled Release 2 beside NG and MF version tags, empty hallway.

If you think a server is already compromised, PaperCut’s FAQ is blunt: secure backups, wipe and rebuild the Application Server, restore from a clean backup taken before the odd behaviour, and run your organisation’s incident process. The vendor says it cannot assess every environment from here. That is the honest limit.

The vendor named the products, named the CVEs, put checksums on a table, told people to pull the web interfaces off the open internet, shipped a first patch in the small hours of 28 August, then shipped a harder Release 2 the same evening with outside researchers on the thanks line, and kept the bulletin live through 30 August with a promise of an official release. That list is the public work. Reprinting an exploit chain is not.

Sunday 30 August 2026 is still inside the bulletin’s own last-updated day. The page has not been withdrawn. Release 2 has not been replaced by the official build yet. v23 and earlier still have no emergency branch on that table. Mobility Print still sits outside the blast. Restrict the Application Server web. Apply Release 2 from PaperCut. Read the vendor indicators on the vendor page if you administer the product. The chain is not the story. The patch is the story. That is the news.