PaperCut NG/MF Patch Bypass - Second Emergency Update
First seen Aug 29, 2026 · Updated Aug 29, 2026
PaperCut has issued a second emergency patch after security researchers found multiple ways to bypass the initial fixes for two actively exploited vulnerabilities in PaperCut NG and MF print management software. Attackers exploiting these flaws can potentially achieve unauthorized access or remote code execution, prompting urgent re-patching for organizations still running vulnerable versions.
Technical Analysis
The vulnerabilities affect PaperCut NG and MF print management software and were previously addressed in an initial emergency patch that has now been shown to be bypassable by researchers, indicating the original fix did not fully close the attack surface. The nature of prior PaperCut flaws in this family typically involves authentication bypass and path traversal leading to remote code execution on the application server. Active exploitation in the wild means threat actors, including ransomware affiliates, have historically leveraged these flaws for initial access and lateral movement within enterprise networks. Organizations running AI agent systems or LLM-based tooling on servers that also host or integrate with PaperCut print management infrastructure could face credential theft or lateral compromise if the print server shares a network segment or authentication domain with agent orchestration hosts, making prompt patching relevant to overall agent pipeline security.
Affected Systems
PaperCut NG and PaperCut MF (all versions vulnerable to the original flaws prior to the second emergency patch); specific version ranges not detailed in source, administrators should consult PaperCut's official security bulletin
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source reporting
Remediation Steps
- 1
Apply the second emergency patch
Immediately update PaperCut NG and MF to the latest patched version released by PaperCut that addresses the bypass techniques.
- 2
Review prior patch effectiveness
Organizations that applied only the first emergency patch should assume it may have been insufficient and verify current patch level against PaperCut's official advisory.
- 3
Network segmentation
Restrict access to PaperCut application servers to trusted internal networks and limit exposure of admin interfaces to the internet.
- 4
Monitor for exploitation indicators
Review PaperCut server logs for unusual authentication attempts, unexpected script execution, or anomalous outbound connections.
- 5
Credential rotation
Rotate any credentials or API keys stored on or accessible from PaperCut servers, especially if those servers interact with broader IT or automation/agent infrastructure.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.