Two recently patched PaperCut zero-day vulnerabilities are being exploited to steal data from print-management servers, security researchers have warned.
The flaws, tracked as CVE-2026-81578 and CVE-2026-82078, affect PaperCut NG and MF. When used together, they can allow an attacker to bypass authentication and achieve remote code execution on an exposed server.
PaperCut Software issued emergency updates on Thursday and Friday, alongside indicators of compromise intended to help organisations identify and block attacks. The company has not publicly attributed the campaign or detailed what attackers have done after gaining access.
Threat intelligence firm Defused said it had detected exploitation in its honeypots from late on 29 August. It said one attacker was abusing the authentication bypass to take control of PaperCut’s external user-lookup function and extract database tables through the Derby database engine.
“An actor is abusing the auth bypass to hijack PaperCut’s external user-lookup,” Defused said. “Unlike the RCE path in public writeups, the actor goes for data theft – dumping DB tables via Derby.”
PaperCut says its software is used by about 100 million people across more than 70,000 organisations, including major businesses, government agencies and educational institutions. That broad deployment has made the platform an established target for criminal and state-backed hacking groups.
More than 800 PaperCut servers exposed online
Internet security organisation Shadowserver is currently tracking more than 800 PaperCut NG and MF servers accessible from the internet. The figure does not show how many systems have already been patched, are honeypots or remain vulnerable.
Organisations running the software have been urged to apply the emergency updates and review PaperCut and network logs for the indicators supplied by the company. Internet-facing print servers should also be restricted where possible.
PaperCut vulnerabilities have previously been used for both ransomware attacks and espionage. In 2023, the LockBit and Clop gangs were linked to exploitation of flaws that enabled remote code execution and information disclosure, while Microsoft said Iranian groups MuddyWater and APT35 had also joined the campaign.
The FBI and the US Cybersecurity and Infrastructure Security Agency later warned that the Bl00dy ransomware group was exploiting the same 2023 remote-code-execution flaw to gain an initial foothold in victims’ networks. CISA also listed another PaperCut remote-code-execution vulnerability, CVE-2023-2533, as actively exploited in July 2025.
