Summary
- PaperCut has confirmed customer incidents involving actively exploited NG/MF vulnerabilities.
- A second wave is hitting unpatched public servers and showing more sophisticated post-compromise activity.
- NHS England assesses continued exploitation as almost certain and has updated its cyber alert following Emergency Patch Release 3.
PaperCut has warned that attacks against internet-facing NG and MF print-management servers have entered a second wave, with more sophisticated activity appearing on systems that remain unpatched.
PaperCut confirmed customer incidents while investigating active exploitation of vulnerabilities affecting its self-hosted software and issued a third emergency patch on 1 September.
The company said the latest attack wave is targeting servers that are still publicly accessible and have not been fully patched. Its field observations indicate more sophisticated post-compromise behaviour than was seen during the opening days of the incident.
Two vulnerabilities are central to the response. CVE-2026-82078 involves unsafe dynamic class loading and can lead to arbitrary Java bytecode execution where an attacker is able to manipulate relevant configuration. CVE-2026-81578 is an access-control weakness that can allow unauthorised changes to system configuration under specific conditions.
Emergency Patch Release 3 supersedes the previous emergency releases for versions 24, 25, and 26. PaperCut said it adds further hardening against potential attack chains and resolves regressions affecting SAML authentication and older Microsoft SQL Server environments.
The response has acquired direct UK public-sector relevance through NHS England. Its National Cyber Security Operations Centre has updated an alert covering the vulnerabilities and assesses continued exploitation as almost certain.
Print-management infrastructure can sit in an awkward position within enterprise networks. The servers are operationally mundane enough to be overlooked during higher-level architecture reviews, but they often interact with identity systems, databases, user directories, print servers, and large numbers of endpoints. An attacker gaining server-level execution may therefore acquire a useful position for persistence or onward access.
Past exploitation of print-management products has also shown the danger of leaving administrative interfaces internet-accessible. External exposure converts vulnerabilities that might otherwise require internal access into remotely reachable attack paths and reduces the amount of reconnaissance needed to find targets.
PaperCut’s emergency response reflects that distinction. Alongside patching, the company has repeatedly told customers with public-facing Application Servers to restrict web interfaces to trusted addresses and remove unnecessary internet exposure.
That advice does not establish whether a system has already been compromised. Once exploitation is confirmed in the wild, patching and exposure reduction address the vulnerability but do not by themselves remove persistence, stolen credentials, or other changes left by an attacker. PaperCut has separately published indicators of compromise and investigation material for affected organisations.
The use of successive emergency releases also creates an operational burden. Organisations that applied an earlier emergency patch need to ensure they have moved to the latest release, while environments running older major versions face a larger upgrade requirement before receiving the current mitigations.
NHS England’s involvement illustrates how a software vulnerability can become a sector-resilience issue even when the affected product is not a clinical system. Print infrastructure is widely deployed across healthcare, education, government, and other distributed estates, where exposure and patching consistency can vary significantly between sites.
PaperCut’s investigation remains active. The appearance of a more capable second wave means the risk is no longer confined to opportunistic probing of a newly disclosed weakness: confirmed incidents are now providing evidence of attackers developing their post-compromise activity while unpatched systems remain available.





