<img alt="" src="https://secure.easy0bark.com/244345.png?trk_user=244345&amp;trk_tit=jsdisabled&amp;trk_ref=jsdisabled&amp;trk_loc=jsdisabled" height="0" width="0" style="display:none;">
Skip to content
Contact Us
    Published: August 27, 2026
    Updated: September 4, 2026

    URGENT: PaperCut NG/MF Security Advisory, immediate action required for internet-facing servers

    Last updated: September 1st, 2026

    PaperCut published an urgent security advisory on August 27th, 2026 covering PaperCut NG and PaperCut MF. PaperCut has confirmed active exploitation of vulnerabilities in the software, along with confirmed customer incidents. All versions of PaperCut NG and MF are affected.

    An emergency patch is available for v24, v25, and v26. This page sets out what UBEO recommends. PaperCut's own bulletin, linked below, is the authoritative source for the latest information.

    Internet-facing servers are the priority

    The advisory applies to every PaperCut NG and MF installation, but the immediate risk is to Application Servers that are accessible from the public internet. Organizations running an internet-facing PaperCut Application Server should treat this as an emergency. Installations reachable only from within an internal network carry lower immediate risk, though the emergency patch should still be applied.

    Immediate action required

    Restricting access is the first priority for any server reachable from the public internet, ahead of any update. PaperCut's instruction is as follows:

    "If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).

    Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server's web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity."

    Emergency Patch Release 3

    PaperCut has released Emergency Patch Release 3 for PaperCut NG and MF v24, v25, and v26. It supersedes the emergency patch published on August 27th and includes additional hardening. PaperCut recommends that all customers install Emergency Patch Release 3, including those who have already applied the earlier patches.

    UBEO's recommendation is to install the patch as soon as possible for PaperCut Servers that are accessible from the internet, or if you’re not sure.

    Versions prior to v24

    No patch is available for PaperCut NG or MF v23 and earlier. Those installations should be upgraded to the latest version.

    This does not need to be two separate steps. The patches listed on PaperCut's advisory are full installers, so downloading the v26 installer and running it over an existing installation upgrades the server to v26 and applies the fix in one step. Follow PaperCut's standard upgrade procedure.

    Until that upgrade is complete, the access restrictions described above remain the essential protection.

    Before updating:

    • Servers should be backed up first, and the backup confirmed good before the update begins.

    • Site Servers and any secondary or print servers should be updated as well, not only the Application Server. Print Deploy and Mobility Print are not affected and do not need updating.

    Please note:

    • This is an emergency patch and has not gone through PaperCut's normal release process.

    • Customers whose Maintenance and Support (M&S) is current are entitled to install the update or to upgrade to the latest version.

    • Sites using an external database for card or ID number lookups have an additional post-install step. See the FAQ section of PaperCut's bulletin for details. Most sites do not use this feature.

    Vulnerabilities addressed:

    • PaperCut has published two CVEs, both addressed in Emergency Patch Release 2:

    • CVE-2026-82078, unsafe dynamic class loading in the database connector. Rated 9.4, critical.

    • CVE-2026-81578, authentication bypass in the web management interface. Rated 8.8, high.

    Full advisory and upgrade guidance

    PaperCut's security bulletin is the authoritative source, and carries the latest information including technical detail, indicators of compromise, and the patch downloads:

    https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory

    PaperCut's general upgrade guidance:

    https://www.papercut.com/help/manuals/ng-mf/common/upgrade/

    Assistance

    Applying the update in-house will likely be more expeditious, and UBEO's recommendation. Customers who would prefer that UBEO handle the update can contact the UBEO Help Desk to schedule a time. UBEO and Papercut support have a higher than normal volume and lead times to assist with the update.

    If you would like UBEO’s assistance, please contact the UBEO Help Desk at helpdesk@ubeo.com or to call, go to https://info.ubeo.com/customer-portal and choose your region and correct phone number.

     

    Caleb Hansen

    Caleb supports and manages a great team that implements enterprise software solutions and delivers Managed IT Services. The team has expert knowledge of our products and services which include Canon, Ricoh, HP, uniFLOW, PaperCut, Laserfiche, and more. Our goal is to provide technical support with uncommonly great...

    Other posts you might be interested in