Column 1
Skip to content

PaperCut NG/MF: Move From Emergency Patches to Maintenance Releases

September 10, 2026

Security maintenance notice, September 10, 2026: PaperCut has released standard NG/MF maintenance versions that replace its emergency patches for CVE-2026-81578 and CVE-2026-82078. The vendor has confirmed exploitation of the underlying issues. Fix I.T. Phill has not assessed your PaperCut deployment.

Choose the Right Maintenance Release

The official PaperCut bulletin lists NG and MF releases 26.0.5, 25.0.13 and 24.1.10. Match your supported product branch before selecting an installer. These are the bulletin’s maintenance releases, not a claim that every later installation or component is affected.

Unpatched, or Emergency Patch Release 1 or 2: upgrade promptly. Verified Emergency Patch Release 3: the vendor says this already protects against the described issues, so migration to a standard maintenance release can follow your normal schedule.

Confirm Product and Component Scope

The bulletin covers PaperCut NG/MF. Update the relevant Application Server, Site Servers and secondary print servers. Do not extend this advisory to PaperCut Hive, Pocket, Mobility Print or Print Deploy components that the vendor identifies as unaffected.

CVE-2026-81578 concerns unauthenticated access-control failure; CVE-2026-82078 concerns code execution with high-privileged configuration access. These are distinct prerequisites, not a claim that every individual flaw independently grants unauthenticated code execution.

Prepare a Controlled Maintenance Window

  • Record the installed edition, branch and emergency patch history in your private maintenance record. A familiar version label alone may not identify an emergency-patched build.
  • Assign a maintenance owner and agree on a service window with the teams that depend on printing. Confirm your organization’s approved recovery procedure and available recovery evidence; do not change backup schedules as part of an advisory check.
  • Read the release notes linked from the vendor bulletin. Identify authentication, card lookup and multi-server workflows that your deployment actually uses, and include those workflows in the acceptance checklist.
  • Obtain software through the vendor’s official download route and verify the corresponding published checksum. Use the documented upgrade procedure for your edition and branch.

Verify Service and Recovery Separately

After maintenance, confirm the installed maintenance version on each relevant server. Test a normal user sign-in, an authorized print job, job release and the configured supporting workflows. Record the result and investigate failures before closing the maintenance window.

Installing updated packages alone does not establish that an earlier compromise has been removed. If compromise is suspected, preserve evidence privately and involve your incident-response team and PaperCut support. This guide does not provide a forensic clearance or recommend testing exploit techniques against a production server.

Source Timing and Support

The bulletin began on August 27, 2026. Its maintenance-release update is dated September 10 at 2:00 pm AEST (04:00 UTC), with a later FAQ update at 3:54 pm AEST (05:54 UTC). This guide explains that maintenance transition; it is not announcing a newly discovered September 10 zero-day.

For adjacent hosted services, see our WordPress support and Ubuntu .NET maintenance guide. PaperCut-specific incident recovery should follow the vendor’s support guidance.

Feature image: a general server-administration illustration, not a product-interface screenshot or evidence from a customer environment.