Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.
PaperCut Software released two sets of emergency patches to address the vulnerabilities on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks. However, the company has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.
Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby."
Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks.
PaperCut servers exposed online (Shadowserver)
Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years.
A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.
... continue reading