PaperCut Software, whose print management software is used by 100 million users across more than 70,000 organizations, released emergency patches last Thursday and Friday to address the flaws, tracked as CVE-2026-81578 and CVE-2026-82078. The two vulnerabilities can be chained to bypass authentication and achieve remote code execution on vulnerable servers.
Over the weekend, Defused confirmed attackers were exploiting the flaws in the wild to steal data from victims' servers. "We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said in a post. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby."
Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, though it is unclear how many are honeypots or have already been secured. PaperCut has published indicators of compromise to help defenders block ongoing attacks, but the company has not attributed the attacks or detailed what threat actors are doing after compromising servers.
Both state-backed hacking groups and ransomware gangs have targeted PaperCut security flaws in the past, raising concerns about the current campaign's origin and intent.