Two security vulnerabilities in PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being used in attacks to steal data from compromised servers.
According to PaperCut Software, its print management software is used by approximately 100 million people across more than 70,000 organizations, including major corporations, government agencies, and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the two PaperCut security flaws can be chained to bypass authentication and achieve remote code execution on vulnerable PaperCut NG and MF servers.
PaperCut Software released two emergency patches on Thursday and Friday to address the vulnerabilities. The company also published indicators of compromise and investigation guidance to help defenders identify and stop ongoing attacks. However, PaperCut has not disclosed how the attacks began or explained what threat actors are doing after gaining access to vulnerable servers.
Threat intelligence firm Defused confirmed over the weekend that attackers had begun exploiting the two vulnerabilities to steal data from compromised PaperCut servers.
“Since late yesterday (UTC) (August 29), we have been observing CVE-2026-81578/CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypot,” Defused said. “The attacker is exploiting an authentication bypass to hijack PaperCut’s external user search. Unlike the publicly disclosed remote code execution path, the attacker is conducting data exfiltration by dumping database tables through Derby.”
Internet security watchdog Shadowserver currently tracks more than 800 PaperCut MF and NG servers exposed online. It is not currently known how many of those servers are honeypots or whether they have already been secured against the attacks.

PaperCut vulnerabilities have been repeatedly targeted by both state-sponsored hacking groups and ransomware operations over the past several years.
A critical remote code execution vulnerability, CVE-2023-27350, and a high-severity information disclosure flaw, CVE-2023-27351, were linked to attacks in April 2023 associated with the LockBit and Clop ransomware gangs.
Two weeks later, Microsoft reported that Iranian state-backed hacking groups MuddyWater and APT35 had also exploited the vulnerabilities.
PaperCut’s Print Archiving feature is designed to save documents sent through a PaperCut print server, potentially giving attackers access to sensitive printed files after compromising the server.
In May 2023, the FBI and CISA warned that the Bl00dy ransomware gang had also begun exploiting CVE-2023-27350 to gain initial access to targeted networks.
In July 2025, the Cybersecurity and Infrastructure Security Agency (CISA) reported that another PaperCut remote code execution vulnerability, CVE-2023-2533, was being actively exploited.
The overall prevention score can obscure what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of security defenses can drop sharply.
The Blue Report 2026 evaluates defense techniques across different technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



