This briefing was produced by AI from the linked sources and is scheduled for human editorial review within 24 hours. Read the sources directly for material decisions.
EVIDENCE — On 1 September 2026, PaperCut published Emergency Patch Release 3 for PaperCut NG and MF versions 24, 25, and 26. It supersedes Release 2 and accumulates the earlier emergency fixes; customers do not need to install Releases 1 or 2 first. PaperCut says internet-facing Application Servers should receive Release 3 as soon as possible even if an earlier emergency patch is already installed. CISA added the underlying exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to KEV on 31 August with a 14 September federal remediation date.
WHY THE TARGET MOVED — PaperCut says Release 3 adds hardening that closes additional attack vectors observed being exploited in the wild. It also fixes two regressions introduced during the emergency response: broken SAML login flows and lost support for legacy Microsoft SQL Server drivers used for external card lookups. This is not evidence of a third CVE, nor does the vendor say Release 2 provided no protection. It means the known attack surface and the operational cost of mitigation changed while the incident was still active.
PROTECTION ARRIVED BEFORE CERTAINTY — PaperCut’s incident account says the first customer report arrived on 27 August, the company declared a highest-priority incident, and it chose to ship useful mitigations before it understood the full chain or completed its normal hardware-assisted regression process. Independent researchers then tested those builds and found areas requiring more hardening. As of Release 3, PaperCut still calls the package an emergency patch—not a fully quality-assured maintenance release—and says that official release remains in progress.
FRACTAL INFERENCE — A patch identifier is repeated across tickets, dashboards, images, Site Servers, secondary servers, evidence reports, and executive declarations that the fleet is safe. When the vendor moves from Release 2 to Release 3, every copied assertion can become stale at once. This is an operational inference from the vendor’s supersedence notice—not evidence that every Release 2 deployment was compromised or that Release 3 closes attack paths PaperCut has not claimed to address.
WHAT TO CHECK — Replace every earlier emergency build with Release 3 on NG/MF Application Servers, Site Servers, and secondary or print servers; use the vendor’s version-specific v24, v25, or v26 package; verify the published build number and SHA-256 checksum; and confirm the running build after restart. Customers on version 23 or earlier should follow PaperCut’s direction to upgrade to the latest version. Keep Application Server web access restricted to trusted addresses, preserve logs and endpoint evidence before changes, retest SAML and external card lookups, and continue monitoring the live advisory because the incident and official maintenance release are unfinished. Editorial view: “patched” is a versioned claim, not a permanent state.