PaperCut Software warns that attackers are actively exploiting a previously unknown vulnerability in its PaperCut NG and PaperCut MF print management software. Multiple outlets report that the company says it is aware of confirmed customer incidents and is treating the issue as high priority. Early reporting notes that a CVE assignment had not yet been made when the first guidance and patch was issued.
PaperCut releases emergency fixes for affected versions and later provides additional updates as more details emerge. SecurityWeek and Bleeping Computer both report that a second emergency patch is released after researchers identify additional ways to bypass the initial mitigations. Later coverage states the vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578, with users urged to install patches for PaperCut v25 and v26 and apply recommended mitigations for NG/MF deployments.
Across outlets, the emphasis remains on active exploitation, broad version impact across PaperCut NG and MF, and a staged patching process as the vendor expands technical details. The accounts largely align on what the vendor is doing—issuing emergency updates and responding to new research—rather than on attack specifics.