PaperCut Zero-Day Exploits Linked to Data Theft Attacks
Recently patched PaperCut zero-days used in data theft attacks
Vulnerabilities and Exploitation
Two security flaws in the PaperCut NG and MF print management software, addressed last week following active exploitation, are now being leveraged in data exfiltration campaigns. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, enable threat actors to circumvent authentication mechanisms and achieve remote code execution on affected PaperCut NG and MF servers.
CVE-2026-81578 and CVE-2026-82078
The software, utilized by 100 million users across 70,000 organizations including enterprises, government agencies, and educational institutions, remains a target for malicious actors. PaperCut Software issued emergency updates to resolve the issues on Thursday and Friday, alongside providing indicators of compromise to assist in mitigating ongoing threats.
Impact on Organizations
However, the company has not yet identified the perpetrators or detailed the specific objectives of the attackers following server compromises. Threat intelligence firm Defused confirmed that the vulnerabilities are being exploited in real-world scenarios, with adversaries utilizing the authentication bypass to access PaperCut’s external user-lookup functionality.
Unlike previous exploitation methods involving remote code execution, the current attacks focus on data theft, specifically extracting database tables through the Derby system.
Shadowserver’s Report
Shadowserver, an internet security monitoring organization, reports over 800 PaperCut MF and NG servers exposed to the public internet, though it remains unclear how many are honeypots or have been secured against these threats.
Historical Context
The vulnerabilities follow a pattern of prior attacks targeting PaperCut’s infrastructure. In 2023, a critical remote code execution flaw (CVE-2023-27350) and a high-severity information disclosure issue (CVE-2023-27351) were exploited by ransomware groups such as LockBit and Clop.
Previous Attacks
Microsoft later attributed similar activity to state-sponsored actors including Muddywater and APT35. The attackers exploited the “Print Archiving” feature, which stores documents processed through PaperCut servers, to infiltrate networks.
FBI and CISA Warning
A subsequent warning from the FBI and CISA in May 2023 highlighted the Bl00dy Ransomware group leveraging the same CVE-2023-27350 flaw for initial network access.
CISA’s July 2025 Alert
In July 2025, CISA flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited.
Recent Analysis and Recommendations
Recent analysis by The Blue Report 2026, which evaluated security measures across 338 million simulations, revealed that 37% of malicious activities are blocked when attackers possess valid credentials.
The report underscores the importance of layered defense strategies to counter evolving threats.
Call to Action
Organizations using PaperCut NG or MF are urged to apply the latest patches immediately and monitor for signs of unauthorized access. The ongoing exploitation of these vulnerabilities highlights the risks associated with unpatched systems and the need for continuous threat monitoring.
