• News/
  • bleepingcomputer-20260901074824

Recently patched PaperCut zero-days used in data theft attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 1, 2026
·
Updated

Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers. PaperCut Software released three sets of emergency patches to address the vulnerabilities on Thursday, Friday, and Tuesday, "to rush mitigations to customers who might not be able to remove their servers from the internet." "The first release was an emergency mitigation. The next release added further hardening as we understood more," explained PaperCut CEO Chris Dance today. "We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon." The company has also published indicators of compromise to help defenders block ongoing attacks, but it has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers. "We recommend all customers with internet-facing Application Servers install Release 3 as soon as possible, even if they have already applied an earlier emergen...

Read full article

Affected Software

1 affected component
PaperCut Software PaperCut NG and MF print management software>=unknown

Frequently Asked Questions

1

Which PaperCut deployments are affected by these vulnerabilities?

Vulnerable PaperCut NG and MF print management servers are affected. The flaws can be chained to bypass authentication and achieve remote code execution on those servers.

2

What malicious activity has been observed following exploitation?

The two vulnerabilities are being abused in data theft attacks. They had already been exploited as zero-days before PaperCut Software released patches.

3

What remediation is available?

PaperCut Software issued three sets of emergency patches on Thursday, Friday, and Tuesday. The company says the first was an emergency mitigation and later releases added hardening, with a fully QA- and regression-tested official release planned.

4

What can defenders use to investigate or block exploitation?

PaperCut Software has published indicators of compromise to help defenders block the activity. Organizations should use the emergency patches and the published indicators of compromise.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203