Security firm watchTowr said on 9 October that PaperCut's print software had a chain of flaws letting an outsider run commands without logging in. PaperCut warned on 27 August 2026 that attackers were using a flaw, but it had no patch yet. watchTowr said only two flaws were used in attacks: CVE-2026-81578, a login bypass, and CVE-2026-82078, which runs commands after login. watchTowr found the later patch bypasses and a new command flaw, CVE-2026-82077, while studying PaperCut's fixes.
watchTowr did not report attacks using those later findings. It did not say how many organisations were hit or who was behind it. It said the web framework, Apache Tapestry 3, lets one request name several pages, and PaperCut checks permissions only on the first. With no one permission check across all pages, watchTowr said, tracking every page is hard. Builds 26.0.4-PO 76530 and 26.0.5 fix its newest two findings. One finding, WT-2026-0141, has no CVE number.
In watchTowr's account, each patch closed one route and another was found. Patching alone may not be enough. Budget owners can ask whether the admin interface is open to the internet, who owns the print server, and how fast the vendor fixes problems. watchTowr says schools, hospitals, governments and law firms use PaperCut.