PaperCut Zero-Days Weaponized: Data Theft Attacks Follow Emergency Patches

The cybersecurity landscape has shifted once again as two recently patched zero-day vulnerabilities in PaperCut NG and MF print management software are now being actively exploited in targeted data theft attacks. Tracked as CVE-2026-81578 and CVE-2026-82078, these critical flaws allow attackers to bypass authentication and achieve remote code execution on vulnerable servers, with threat actors now leveraging them to exfiltrate sensitive database information. With over 100 million users across 70,000 organizations relying on this software, the urgency for administrators to apply the latest emergency patches has never been more critical.

PaperCut Software, the vendor behind the ubiquitous print management platform, has been scrambling to contain the fallout from these actively exploited vulnerabilities. The company released three separate sets of emergency patches in rapid succession—on Thursday, Friday, and Tuesday—in a bid to "rush mitigations to customers who might not be able to remove their servers from the internet." This unprecedented response highlights the severity of the situation and the delicate balance between speed and security in the face of active exploitation.

"The first release was an emergency mitigation. The next release added further hardening as we understood more," explained PaperCut CEO Chris Dance in a statement addressing the ongoing crisis. "We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon." This candid admission underscores the evolving nature of the threat and the challenges vendors face when responding to zero-day vulnerabilities that are already being weaponized in the wild.

The Technical Breakdown: Authentication Bypass and RCE

The two security flaws, CVE-2026-81578 and CVE-2026-82078, represent a dangerous combination when chained together by skilled attackers. The first vulnerability enables authentication bypass, allowing threat actors to circumvent login mechanisms and gain unauthorized access to PaperCut servers. The second flaw facilitates remote code execution, giving attackers the ability to run arbitrary code on compromised systems. When combined, these vulnerabilities create a critical attack chain that can completely compromise vulnerable PaperCut NG and MF print management servers.

What makes this particularly concerning is the widespread adoption of PaperCut software across critical sectors. The platform is used by large corporations, state agencies, and educational institutions worldwide, making it an attractive target for both financially motivated cybercriminals and state-sponsored hacking groups. Print management servers often sit on internal networks with access to sensitive documents and user credentials, making them a valuable entry point for broader network compromise.

Data Theft Campaign Observed in the Wild

Over the weekend, threat intelligence firm Defused confirmed that attackers have already begun exploiting these vulnerabilities in active campaigns. "We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused reported. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby."

This observation reveals a strategic shift in attacker behavior. Rather than pursuing the more dramatic remote code execution path that would typically lead to ransomware deployment or malware installation, the threat actors are opting for a quieter, more insidious approach: data exfiltration. By dumping database tables via the Derby database system, attackers can steal user credentials, print job histories, and other sensitive information without triggering the alarms that typically accompany ransomware attacks or malware infections.

The scale of exposure is significant. Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, though it remains unclear how many of these are honeypots or have already been secured against these attacks. This number represents a substantial attack surface for malicious actors to target, and the actual number of compromised systems could be significantly higher than what is publicly known.

Indicators of Compromise and Mitigation Guidance

In response to the active exploitation, PaperCut Software has published indicators of compromise (IOCs) to help defenders detect and block ongoing attacks. However, the company has yet to attribute the attacks to specific threat actors or explain what the attackers are doing after compromising vulnerable servers. This lack of attribution makes it more difficult for security teams to anticipate attacker behavior and implement targeted defenses.

The company's guidance is unequivocal: "We recommend all customers with internet-facing Application Servers install Release 3 as soon as possible, even if they have already applied an earlier emergency release." This recommendation applies even to organizations that have already deployed previous emergency patches, as the latest release includes additional hardening measures based on the evolving understanding of the attack vectors.

A History of Targeting: PaperCut as a Prime Target

This is not the first time PaperCut vulnerabilities have been exploited in the wild. The software has a well-documented history of being targeted by both state-backed hacking groups and ransomware gangs. In April 2023, a critical remote code execution vulnerability (CVE-2023-27350) and a high-severity information disclosure flaw (CVE-2023-27351) were chained together in attacks linked to the LockBit and Clop ransomware gangs. These attacks demonstrated the real-world impact of PaperCut vulnerabilities and the willingness of cybercriminals to exploit them for financial gain.

Microsoft revealed just two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the exploitation efforts. These sophisticated threat actors abused the 'Print Archiving' feature, which is designed to save all documents sent through PaperCut printing servers, to steal sensitive information from compromised networks. The involvement of state-sponsored actors elevated the threat level significantly, as these groups typically have more resources and advanced capabilities than typical cybercriminal organizations.

The targeting continued into May 2023 when the FBI and CISA issued a joint warning that the Bl00dy Ransomware gang had begun exploiting the CVE-2023-27350 flaw for initial access to targets' networks. More recently, in July 2025, CISA flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited, further cementing PaperCut's status as a prime target for malicious actors.

The Broader Context: Valid Credentials and Prevention Gaps

The current exploitation of PaperCut vulnerabilities highlights a broader issue in cybersecurity: the limitations of prevention mechanisms once attackers gain valid credentials. According to the Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments, overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply, with only 37% of their actions being blocked.

This statistic underscores the importance of defense-in-depth strategies and the need for organizations to focus not just on preventing initial access but also on detecting and containing attacker activity after a breach occurs. The PaperCut zero-day exploitation serves as a stark reminder that even well-patched environments can be compromised through unknown vulnerabilities, and organizations must have robust detection and response capabilities in place.

Conclusion: Immediate Action Required

The exploitation of CVE-2026-81578 and CVE-2026-82078 in data theft attacks represents a significant threat to organizations using PaperCut NG and MF print management software. With over 800 exposed servers tracked online and active exploitation campaigns already underway, the window for proactive defense is rapidly closing. Administrators must prioritize applying the latest emergency patch release, reviewing indicators of compromise, and monitoring their networks for signs of unauthorized access or data exfiltration.

The rapid evolution of these attacks—from initial exploitation to data theft campaigns—demonstrates the adaptability of threat actors and the importance of staying ahead of emerging threats. As PaperCut continues to develop and release additional patches, organizations must remain vigilant and treat this as an ongoing incident rather than a one-time fix. The cybersecurity community will be watching closely to see how this situation unfolds and what lessons can be learned to prevent similar attacks in the future.