Critical Authentication Bypass and Remote Code Execution Flaws Prompt Emergency Patch 2 for PaperCut NG/MF
What Happened — PaperCut disclosed two actively‑exploited zero‑day vulnerabilities (CVE‑2026‑81578, CVE‑2026‑82078) in its NG/MF print‑management suite. The flaws allow unauthenticated attackers to bypass authentication and execute arbitrary Java bytecode on the server. A second emergency patch was released to harden the fixes after researchers demonstrated bypass techniques.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous vulnerability monitoring and rapid remediation to satisfy SOC 2 CC6.1 (System Operations) and CC7.2 (Risk Management).
- Provides a concrete example of why organizations must collect immutable evidence of patch deployment for auditability.
- Highlights the importance of mapping vendor‑provided controls to your own control framework to prove due diligence.
Who Is Affected – Enterprises that deploy PaperCut NG/MF across sectors such as education, healthcare, finance, and professional services.
Recommended Actions –
- Map the two CVEs to the relevant SOC 2 security criteria in your risk register.
- Deploy Emergency Patch 2 immediately on all PaperCut servers and capture deployment logs as audit evidence.
- Integrate automated vulnerability scanning to detect any re‑emergence of the flaws.
- Document the remediation workflow in your continuous‑compliance platform.
Source: BleepingComputer article
Technical Notes – CVE‑2026‑81578 (Auth‑bypass, CVSS 8.8) exploits unchecked admin‑function calls; CVE‑2026‑82078 (Unsafe dynamic class‑loading, CVSS 9.4) permits arbitrary Java bytecode execution via manipulated driver names. Both affect PaperCut NG/MF versions 25‑26.