PaperCut Vulnerability Exploited in Active Cyber Attacks
Recent cyberattacks targeting PaperCut NG/MF print management solutions have intensified, with threat actors transitioning from reconnaissance to direct system exploitation.
Vulnerabilities and Vendor Response
The vendor initially alerted users to a zero-day vulnerability on August 27, which was later found to be part of a broader attack chain involving two separate flaws. These vulnerabilities, designated CVE-2026-82078 and CVE-2026-81578, allow unauthenticated adversaries to bypass authentication mechanisms and execute arbitrary code on affected systems. PaperCut released emergency patches following the discovery, but attackers quickly adapted, prompting the vendor to issue a second update. A comprehensive fix addressing both vulnerabilities is in development.
CVE Details
The vulnerabilities, CVE-2026-82078 and CVE-2026-81578, enable unauthenticated adversaries to bypass authentication mechanisms and execute arbitrary code on affected systems.
Attack Patterns and Tactics
Exposure management firm WatchTowr reported a significant shift in attack patterns, noting that malicious actors are now engaging in hands-on-keyboard activities rather than passive scanning. Jake Knott, head of threat intelligence at WatchTowr, highlighted the evolution of tactics, stating that attackers are employing sophisticated methods to move laterally within compromised networks.
“This activity represents a marked increase in complexity compared to earlier stages,” Knott explained. “Some operations are specifically designed to enable internal network access, allowing attackers to expand their reach.”
The firm’s analysis also revealed the deployment of remote access tools on breached systems, indicating a focus on prolonged access and data exfiltration. Security researchers at Huntress and Rapid7 have published technical details on the vulnerabilities, while CISA added both flaws to its Known Exploited Vulnerabilities catalog on Monday. Federal agencies are mandated to resolve the issues by September 14.
Security Recommendations
ShadowServer data estimates over 1,000 PaperCut NG/MF instances are publicly accessible, increasing their risk of compromise. WatchTowr warned that unpatched systems exposed to the internet in the past few days are likely already infiltrated.
“Organizations should initiate incident response protocols immediately,” Knott advised. “While patching will prevent new intrusions, existing threats may still maintain access and escalate their activities.”
The vulnerabilities enable attackers to bypass authentication and execute code remotely, making them highly dangerous for unsecured environments. Security teams are urged to prioritize mitigation efforts and monitor for signs of compromise, including unusual network traffic or unauthorized access attempts.
