PaperCut has released a second emergency patch for two actively exploited vulnerabilities in PaperCut NG and MF, its print management software, according to BleepingComputer. The update follows an initial emergency fix for PaperCut NG/MF versions 25 and 26 that the company issued after warning customers that attackers were exploiting a zero-day vulnerability against customer servers. BleepingComputer reports that PaperCut has now disclosed identifiers and technical details for the two issues: CVE-2026-82078 and CVE-2026-81578. The vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers, according to the report. CVE-2026-81578 is described as a high-severity authentication bypass vulnerability in the PaperCut NG/MF web management interface, with a severity score of 8.8. PaperCut’s updated advisory, as quoted by BleepingComputer, says unauthenticated remote requests targeting administrative functions can, under specific conditions, trigger backend actions before access validation checks are completed. The second flaw, CVE-2026-82078, is described as a critical unsafe dynamic class-loading vulnerability in PaperCut’s database connection utilities, rated 9.4. BleepingComputer reports that the issue stems from the application loading database driver classes based on configurable driver names without validating them against an approved allowlist. PaperCut’s advisory says that if an attacker can manipulate system configuration parameters, arbitrary Java bytecode on the application classpath can execute under the security context of the PaperCut server process. The second patch was released Friday as Emergency Patch Release 2. According to BleepingComputer, PaperCut said the update adds hardening developed after further analysis by its internal security team and external researchers at Huntress and watchTowr. The company is urging all customers to install Release 2 even if they already installed the first emergency patch. The updated fix follows watchTowr’s statement that its researchers fully reproduced the vulnerabilities, found multiple bypasses for the original patch, and identified an additional authentication bypass vulnerability, BleepingComputer reports. watchTowr also said the vulnerabilities allow unauthenticated attackers to bypass authentication and gain remote code execution on affected PaperCut NG/MF instances. Emergency Patch Release 2 is available for PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS, according to BleepingComputer. The report says BleepingComputer has asked Huntress for more detail on its analysis and will update if it receives a response. Who benefits: PaperCut customers who move quickly to Emergency Patch Release 2 reduce exposure to the reported bypass chain. Security teams also benefit from the newly disclosed CVE identifiers and severity ratings for tracking and prioritization. Who's exposed: Organizations running affected PaperCut NG/MF instances remain exposed if they have not applied Release 2. The provided reporting does not quantify the number of affected customers or observed victims.