PaperCut has shipped a second emergency patch for two zero-day vulnerabilities in its NG and MF print management software after researchers found multiple ways to bypass the first fix. Both flaws — CVE-2026-82078 (CVSS 9.4, critical) and CVE-2026-81578 (CVSS 8.8, high) — are being chained by attackers to bypass authentication and run code on unpatched servers. CISA added both to its Known Exploited Vulnerabilities catalogue on 31 August.
Why This Matters for Australian Businesses
PaperCut is one of the most common print management platforms in Australian offices, schools and professional-services firms. We see it deployed across a significant share of the SMB environments we manage, and many organisations treat their print server as “set and forget” infrastructure — exactly the kind of blind spot attackers count on. The fact that the initial emergency patch was bypassed within 24 hours is a pattern we’re seeing more frequently: vendors shipping under pressure, researchers finding gaps almost immediately, and businesses left exposed between rounds of fixes.
What to Do Right Now
Update every PaperCut NG and MF instance — including Site Servers — to Emergency Patch Release 2 for your version (24, 25 or 26). If you’re still on version 23 or earlier, upgrade to the latest branch first. While you’re at it, lock down the web management console to trusted IPs only — it should never face the public internet. Check your server.log for lines containing No suitable driver found for jdbc:no:x or Database error looking up cardID: VALUES CAST — either is a sign someone has already tried the exploit.
Not sure whether your print servers are exposed or patched? Get in touch — our team can audit your PaperCut deployment and close the gap before attackers find it.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
