Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
SecurityAI-assisted

PaperCut ships second emergency patch after researchers break the first fix within days

Two chained flaws in the print-management software allow unauthenticated remote code execution. Attackers were already exploiting one of them before the first patch landed.

PaperCut ships second emergency patch after researchers break the first fix within days

Printer-management software rarely makes headlines, which is part of why this one is worth paying attention to. PaperCut, whose NG and MF products sit behind print queues in universities, hospitals and corporate offices worldwide, shipped an emergency patch, watched researchers find a way around it within days, and then shipped a second emergency patch.

The more severe of the two flaws, CVE-2026-82078, rated 9.4, is an unsafe dynamic class-loading bug in PaperCut's database connection utilities. The application loads database driver classes based on configurable driver names without checking them against any approved allowlist. An attacker who can manipulate system configuration parameters can use that gap to execute arbitrary Java bytecode already sitting on the application's classpath, running under the same security context as the PaperCut server process itself.

The second, CVE-2026-81578, rated 8.8, is an authentication bypass in the PaperCut NG/MF web management interface. Under specific conditions, unauthenticated remote requests aimed at administrative functions can trigger backend actions before the software finishes checking whether the requester was allowed to make them in the first place.

Printer-management software rarely makes headlines, which is part of why this one is worth paying attention to.
Benjamin Scott · The Hacking Post

Chained together, the two flaws add up to unauthenticated remote code execution, and attackers were reportedly already exploiting them before the first round of patches shipped. All versions of PaperCut NG and MF prior to August 27 are affected. PaperCut worked with researchers at watchTowr and Huntress after the initial patch turned out to have gaps, and published Emergency Patch Release 2 on August 28, covering NG/MF versions 24, 25 and 26 across Windows, Linux and macOS.

A patch that gets broken within 24 to 48 hours of release is not a rare event in this industry, but it is a useful data point on how fast serious researchers now turn a public advisory into a working bypass. Organizations running PaperCut have essentially no reason left to wait: version 26, the newest release line, is the one getting the fastest attention from both attackers and defenders right now.

Advertisement

PaperCut has been down this road before. A 2023 vulnerability in the same product line was picked up by ransomware affiliates within days of disclosure and used to breach managed service providers, giving attackers a foothold into every downstream client those MSPs served. That history is part of why watchTowr and Huntress moved as fast as they did this time around, and part of why the second emergency patch arrived within roughly 48 hours of the first one being shown not to hold. Print infrastructure is easy to overlook precisely because nobody thinks of a printer queue as a security boundary, until it turns out to be one.

Based on reporting by BleepingComputer.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories