Skip to content
Tech News
← Back to articles

Recently patched PaperCut zero-days used in data theft attacks

read original more articles
Why This Matters

The recent exploitation of patched vulnerabilities in PaperCut print management software highlights ongoing risks for organizations relying on this widely used platform. These zero-day attacks underscore the importance of timely patching and vigilance to prevent data theft and unauthorized access, especially given the software's extensive user base across various sectors.

Key Takeaways

Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.

According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.

Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.

PaperCut Software released two sets of emergency patches to address the vulnerabilities on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks. However, the company has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.

Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.

"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby."

Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks.

PaperCut servers exposed online (Shadowserver)

​Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years.

A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.

... continue reading