Attackers exploit patched PaperCut flaws to steal data from print servers
Hackers are actively exploiting two recently disclosed PaperCut NG and MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and steal data from print management servers. PaperCut issued emergency fixes last week, but researchers at Defused say attackers are using the bypass to hijack the software's user-lookup function and dump database tables rather than pursue remote code execution as earlier reports suggested. Over 800 PaperCut servers remain exposed online according to Shadowserver, and PaperCut has not yet attributed the attacks or detailed post-compromise activity.