Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers. PaperCut Software released three sets of emergency patches to address the vulnerabilities on Thursday, Friday, and Tuesday, "to rush mitigations to customers who might not be able to remove their servers from the internet." "The first release was an emergency mitigation. The next release added further hardening as we understood more," explained PaperCut CEO Chris Dance today. "We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon." The company has also published indicators of compromise to help defenders block ongoing attacks, but it has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers. "We recommend all customers with internet-facing Application Servers install Release 3 as soon as possible, even if they have already applied an earlier emergen...
Recently patched PaperCut zero-days used in data theft attacks
Affected Software
Frequently Asked Questions
Which PaperCut deployments are affected by these vulnerabilities?
Vulnerable PaperCut NG and MF print management servers are affected. The flaws can be chained to bypass authentication and achieve remote code execution on those servers.
What malicious activity has been observed following exploitation?
The two vulnerabilities are being abused in data theft attacks. They had already been exploited as zero-days before PaperCut Software released patches.
What remediation is available?
PaperCut Software issued three sets of emergency patches on Thursday, Friday, and Tuesday. The company says the first was an emergency mitigation and later releases added hardening, with a fully QA- and regression-tested official release planned.
What can defenders use to investigate or block exploitation?
PaperCut Software has published indicators of compromise to help defenders block the activity. Organizations should use the emergency patches and the published indicators of compromise.