PaperCut NG/MF exploit chain: second attack wave reinforces Release 3 and compromise review

Published 10 Sep 2026 · Severity: critical

CISA added chained PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 to KEV on 31 August 2026. PaperCut confirms customer incidents and now reports a second attack wave against servers that remain publicly accessible and are not fully patched, with more sophisticated post-compromise behaviour than in the first days. Cumulative Emergency Patch Release 3 remains the current emergency fix while the normal maintenance release is still in progress. Restrict public access, apply Release 3 across relevant server roles and investigate exposure rather than treating patching alone as proof of a clean server.