The vendor named it, dated it, and told you to pull the web off the open internet. PaperCut Software published an urgent security bulletin on 27 August 2026, Australian Eastern Standard Time. The objects are PaperCut NG and PaperCut MF. The company said its security response team is investigating active exploitation, that it is aware of confirmed customer incidents, and that the investigation is ongoing. The news is the vendor page, not a break-in.

Immediate action on that page is a network sentence, not a payload. If the Application Server’s web interfaces are reachable from the public internet, restrict them to trusted addresses now. Firewall, network access control, equivalent. Take that step even if you haven’t seen anything odd. Then look at the emergency patch.

Primary is PaperCut’s own bulletin: “URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026),” last updated 30 August 2026. The vulnerability log on papercut.com points at the same date and two CVE identifiers. Huntress and watchTowr are named on the vendor page as external researchers who helped harden Release 2. Huntress also published its own customer note on 27 August, with a 28 August afternoon Eastern update. The calendar on this page follows PaperCut’s timestamps in AEST. Huntress is a second dated clip, not a recipe book.

PaperCut shipped Emergency Patch Release 2 for NG and MF
Original illustration, The Gold Standard art desk (Pablo Picasso).Download

The bulletin’s timeline, as PaperCut printed it, is the spine. 27 August: initial bulletin. 27 August 8:00 p.m. AEST: minor wording. 27 August 9:02 p.m.: investigation update. 28 August 2:10 a.m. AEST: emergency patch for v25 and v26. 28 August 10:43 a.m.: card and ID lookup note. 28 August 8:42 p.m. AEST: Emergency Patch Release 2, additional hardening, thanks to Huntress and watchTowr, plus a security.properties note for a rarely used external card-lookup feature. 28 August 10:08 p.m.: Release 2 for v24. 29 August: FAQs, then a note that some sites saw card lookup and SAML trouble after the patch. 30 August 10:34 a.m. AEST: official release still in progress, support at support.papercut.com, more card-lookup advice. 30 August 3:35 p.m. AEST: more investigation leads added to the bulletin.

Those leads stay on PaperCut’s page for administrators who already run the product. Follow the vendor bulletin. This newspaper isn’t a substitute for it. The file is names, dates, CVEs, who should patch, and what the vendor says to restrict. Not a chain. Not a class-loading walkthrough. Not a request to paste.

Bulletin
A printed urgent security bulletin on a dark print-room desk beside a small application server, no people. Download

Two CVEs are now public on that page. CVE-2026-82078 is unsafe dynamic class loading in the database connector, CWE-470, CVSS 9.4 Critical on the vector PaperCut printed. Mitigated in Emergency Patch Release 2. CVE-2026-81578 is an authentication bypass in the web management interface, CWE-306, CVSS 8.8 High, unauthenticated remote requests that can modify certain system configurations under specific conditions. Also mitigated in Release 2. Those are PaperCut’s sentences. This page won’t unpack “specific conditions” into a lab.

Who is in scope: all versions of PaperCut NG and PaperCut MF, the vendor said. Site servers and secondary print servers should be updated to a patched build, not only the primary Application Server. Print Deploy and Mobility Print are not affected. Mobility Print ports can stay as they are, per the FAQ. Versions before v24: the recommended path is to upgrade to the latest, not to wait for a 23-and-older emergency branch. PaperCut was explicit that this emergency patch is not an official release. Usual process did not run. It is for public-facing servers that cannot take other mitigating action yet. An official release is still being built as of 30 August 10:34 a.m. AEST.

Release 2 is the build this file wants on the page. PaperCut recommends it even if you already installed the first emergency patch. Checksums in SHA256 are on the vendor table for Windows, Linux, and macOS, for MF and NG, for v24, v25, and v26. Print that the table exists. Don’t turn this article into a download mirror. Get the bits from PaperCut. Follow the standard upgrade procedure PaperCut already documents.

A rarely used feature got a properties flag. External database Card/ID number lookups default off after the patch unless you set security.card-number-lookup.enabled=Y in server/security.properties and restart. Most customers won’t need that key. If you use SQL Server for those lookups with the old Sourceforge jTDS driver, PaperCut’s 30 August FAQ says move to the current Microsoft SQL JDBC driver as a first step. SAML and card lookup reports after the patch are under investigation as of 29–30 August. That’s a post-patch support story, not a reason to skip Release 2 if you are on the public internet.

Huntress, 27 August, said it had seen two customer environments, that observed activity looked like discovery, and that it had not seen secondary malware in those recoveries as of that post. A 28 August 2:45 p.m. ET update on that post said PaperCut had shipped Release 2 and assigned the two CVEs. Huntress also wrote that it reproduced a chain in a lab. This newspaper isn’t reproducing it. This newspaper isn’t hosting a proof of concept. Confirmed incidents plus a vendor patch is the news. A lab recreation is a researcher’s note. Keep it off the how-to shelf.

Patch crate
A sealed emergency-patch crate labelled Release 2 beside NG and MF version tags, empty hallway. Download

If you think a server is already compromised, PaperCut’s FAQ is blunt: secure backups, wipe and rebuild the Application Server, restore from a clean backup taken before the odd behaviour, and run your organisation’s incident process. The vendor says it cannot assess every environment from here. That’s the honest limit.

The vendor named the products, named the CVEs, put checksums on a table, told people to pull the web interfaces off the open internet, shipped a first patch in the small hours of 28 August, then shipped a harder Release 2 the same evening with outside researchers on the thanks line, and kept the bulletin live through 30 August with a promise of an official release. That list is the public work. Reprinting an exploit chain isn’t.

Sunday 30 August 2026 is still inside the bulletin’s own last-updated day. The page hasn’t been withdrawn. Release 2 hasn’t been replaced by the official build yet. v23 and earlier still have no emergency branch on that table. Mobility Print still sits outside the blast. Restrict the Application Server web. Apply Release 2 from PaperCut. Read the vendor indicators on the vendor page if you administer the product. The chain isn’t the story. The patch is the story. That’s the news.