PaperCut warned that attackers are actively exploiting vulnerabilities in all versions of its widely deployed NG and MF print-management software, and confirmed real customer incidents. Two flaws are involved: CVE-2026-82078, unsafe dynamic class loading in the database connection utilities that lets an attacker run arbitrary Java bytecode, and CVE-2026-81578, an access-control flaw in the web management interface that lets an unauthenticated attacker change system configuration. PaperCut released emergency out-of-cycle patches for its version 25 and 26 branches, with a version 24 build still in progress, and later issued a hardened second release. PaperCut servers have a history of being targeted by ransomware crews.