Attackers Exploit Recently Patched PaperCut Zero-Days for Data Theft
Two security vulnerabilities in PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. The flaws, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained together to bypass authentication and achieve remote code execution on vulnerable servers. PaperCut's software serves roughly 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
PaperCut Software released two sets of emergency patches on Thursday and Friday and published indicators of compromise to help defenders block ongoing attacks. However, the company has not attributed the attacks or explained what threat actors do after compromising servers. Threat intelligence company Defused confirms that attackers are exploiting the flaws in the wild, saying an actor is abusing the auth bypass to hijack PaperCut's external user-lookup and dump database tables via Derby, focusing on data theft rather than the RCE path described in public writeups.
Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, though it is unclear how many are honeypots or already secured. Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut flaws, including 2023 attacks linked to LockBit and Clop ransomware gangs and the Iranian Muddywater and APT35 groups, which abused the Print Archiving feature. Organizations running PaperCut are urged to apply the emergency patches immediately and review the published indicators of compromise.