PaperCut zero-days exploited in data theft attacks after emergency patches

Attackers chaining auth bypass and RCE flaws to dump databases from exposed servers

edit
By LineZotpaper
Published
Read Time2 min
Two security vulnerabilities in PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being actively abused in data theft attacks, according to threat intelligence company Defused and internet security watchdog Shadowserver.

PaperCut Software, whose print management software is used by 100 million users across more than 70,000 organizations, released emergency patches last Thursday and Friday to address the flaws, tracked as CVE-2026-81578 and CVE-2026-82078. The two vulnerabilities can be chained to bypass authentication and achieve remote code execution on vulnerable servers.

Over the weekend, Defused confirmed attackers were exploiting the flaws in the wild to steal data from victims' servers. "We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said in a post. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby."

Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, though it is unclear how many are honeypots or have already been secured. PaperCut has published indicators of compromise to help defenders block ongoing attacks, but the company has not attributed the attacks or detailed what threat actors are doing after compromising servers.

Both state-backed hacking groups and ransomware gangs have targeted PaperCut security flaws in the past, raising concerns about the current campaign's origin and intent.

§

Analysis

Why This Matters

  • PaperCut is widely deployed in large enterprises, government agencies, and schools — a broad attack surface that could lead to significant data breaches.
  • The shift from remote code execution to data theft suggests attackers are prioritizing exfiltration over disruption, potentially for extortion or espionage.
  • With over 800 servers still exposed online, the window for organisations to patch is closing rapidly.

Background

PaperCut NG and MF are print management solutions used by tens of thousands of organisations worldwide to control printing costs, track usage, and enforce security policies. The software runs on servers often accessible from internal networks and sometimes the internet. Previous vulnerabilities in PaperCut have been exploited by ransomware groups (e.g., Clop) and nation-state actors, making any new unpatched flaw a priority for defenders.

Key Perspectives

PaperCut Software: The company acted quickly with two emergency patches and published Indicators of Compromise. It has not yet identified the attackers or explained the full scope of the data theft. Defenders (IT teams, security vendors): They are racing to apply patches and check for signs of compromise. The use of Derby database dumping means attackers may have extracted user credentials, print logs, and configuration data. Attackers: They are exploiting the auth bypass to steal data rather than execute code, suggesting a different objective — possibly data brokerage, extortion without encryption, or intelligence gathering.

What to Watch

  • Whether PaperCut releases an updated advisory with attribution or additional IoCs as the investigation continues.
  • The number of exposed servers tracked by Shadowserver — a sharp drop would indicate patching is underway; a sustained high count raises risk of mass exploitation.
  • Reports of data leaks or extortion attempts linked to these attacks, which would confirm the theft is for ransom or sale.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.