PaperCut said on 27 August that attackers were already exploiting a vulnerability in PaperCut MF and PaperCut NG, and it published indicators of compromise without a patch. watchTowr later said the issue was not a single bug but a pre-authentication remote-code-execution chain with patch bypasses, tracked by PaperCut as CVE-2026-82077, CVE-2026-82078, and CVE-2026-81578.
The mechanism matters because the first fix covered one route into the same bad behavior, while a second route still reached the vulnerable code path. In plain terms, the patch closed a doorway, not the room, so a single CVE label did not mean the whole product was safe.
For admins running PaperCut as an internal print appliance, the exposure is now product-wide until a fixed version lands; until then, the vendor advisory and hunt data are the only cleanup points. Any environment that treats one patched finding as the end of the story risks leaving another exploitable path in place.
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into singular CVE IDs.