Print management software provider PaperCut has issued a second emergency security update for its PaperCut NG and MF products. The update addresses two vulnerabilities that were being actively exploited in the wild, after security researchers identified methods to bypass the initial fixes released earlier.
What happened
PaperCut released an initial emergency patch to address critical vulnerabilities in its print management software. However, researchers subsequently found that the original fixes could be circumvented, prompting the company to develop and release a second, more robust patch. The vulnerabilities affect both PaperCut NG and MF versions, which are widely used in enterprise and educational environments for print job management and cost tracking.
The company has not disclosed specific details about the nature of the exploits or the number of affected customers, citing ongoing investigations. However, it confirmed that the flaws were being actively exploited prior to the release of the second patch. PaperCut has urged all users to apply the latest update immediately to mitigate potential risks.
What we don't know yet
The exact timeline of the initial exploitation remains unclear, as does the identity of the threat actors involved. PaperCut has not provided details on whether any data breaches or unauthorized access incidents have been linked to these vulnerabilities. Additionally, the company has not specified the technical mechanisms used to bypass the first patch, likely to prevent further exploitation while users update their systems.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 28 Aug 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 3 candidates
- Checking for duplicates — Follow-up story Follow-up on the same exploited PaperCut flaw with new patch details.; matched_article_id=476
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=482 slug=papercut-issues-second-emergency-patch-for-exploited-flaws quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states 'two vulnerabilities' were addressed, but the source text does not specify the number of vulnerabilities (only mentions 'two actively exploited vulnerabilities' in the context of the update, not the count of distinct flaws). The claim should be softened to 'actively exploited vulnerabilities' or clarified if the source implies two distinct flaws.
- Quote integrity: No blockquotes are used in the draft, but the absence is not an issue since the sources do not provide a verbatim quote suitable for direct attribution. Compliance with the rule is maintained.
- No copied phrasing: The draft avoids direct copying of source phrasing, but the opening sentence closely mirrors the source's structure ('PaperCut has released a second emergency security update...'). While not identical, the phrasing could be further restructured to avoid similarity.
- Style compliance: The draft adheres to the structure and tone requirements, but the 'What we don't know yet' section could be merged into 'What happened' or 'Why it matters' to avoid redundancy in a QUICK READ brief. This is a minor structural preference, not a material issue.
- Audience relevance and notability: The story is relevant to hosting, cloud, and enterprise IT professionals managing print infrastructure, but the lack of technical details (e.g., CVEs, attack vectors) limits actionable insights. This is defensible given the sources but could be flagged as thin for a vulnerabilities category.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #59: No candidate sufficiently matches the article topic about PaperCut's emergency security patch for exploited flaws in print management software. The provided candidate (index 0) depicts a generic software interface unrelated to security vulnerabilities or print management, despite the misleading alt text. The article requires imagery related to cybersecurity, patches, exploits, or print management software, none of which are present in the candidates.
- Assigning hero image — Reused library image reused image #19
- Linking related stories — Linked 1 relations from 416 candidates
- Publishing — Published papercut-issues-second-emergency-patch-for-exploited-flaws
- Mastodon — Posted https://mstdn.social/@hostingpaper/117175352172474091


Discussion · coming soon
Be the first to join the thread when community discussion launches.