PaperCut Zero-Day Exploits Linked to Data Theft Attacks

www.news4hackers.com-papercut-zero-day-exploits-linked-to-data-theft-attacks-papercut-zero-day-exploits-linked-to-data-theft-attacks

Recently patched PaperCut zero-days used in data theft attacks

Vulnerabilities and Exploitation

Two security flaws in the PaperCut NG and MF print management software, addressed last week following active exploitation, are now being leveraged in data exfiltration campaigns. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, enable threat actors to circumvent authentication mechanisms and achieve remote code execution on affected PaperCut NG and MF servers.

CVE-2026-81578 and CVE-2026-82078

The software, utilized by 100 million users across 70,000 organizations including enterprises, government agencies, and educational institutions, remains a target for malicious actors. PaperCut Software issued emergency updates to resolve the issues on Thursday and Friday, alongside providing indicators of compromise to assist in mitigating ongoing threats.

Impact on Organizations

However, the company has not yet identified the perpetrators or detailed the specific objectives of the attackers following server compromises. Threat intelligence firm Defused confirmed that the vulnerabilities are being exploited in real-world scenarios, with adversaries utilizing the authentication bypass to access PaperCut’s external user-lookup functionality.

Unlike previous exploitation methods involving remote code execution, the current attacks focus on data theft, specifically extracting database tables through the Derby system.

Shadowserver’s Report

Shadowserver, an internet security monitoring organization, reports over 800 PaperCut MF and NG servers exposed to the public internet, though it remains unclear how many are honeypots or have been secured against these threats.

Historical Context

The vulnerabilities follow a pattern of prior attacks targeting PaperCut’s infrastructure. In 2023, a critical remote code execution flaw (CVE-2023-27350) and a high-severity information disclosure issue (CVE-2023-27351) were exploited by ransomware groups such as LockBit and Clop.

Previous Attacks

Microsoft later attributed similar activity to state-sponsored actors including Muddywater and APT35. The attackers exploited the “Print Archiving” feature, which stores documents processed through PaperCut servers, to infiltrate networks.

FBI and CISA Warning

A subsequent warning from the FBI and CISA in May 2023 highlighted the Bl00dy Ransomware group leveraging the same CVE-2023-27350 flaw for initial network access.

CISA’s July 2025 Alert

In July 2025, CISA flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited.

Recent Analysis and Recommendations

Recent analysis by The Blue Report 2026, which evaluated security measures across 338 million simulations, revealed that 37% of malicious activities are blocked when attackers possess valid credentials.

The report underscores the importance of layered defense strategies to counter evolving threats.

Call to Action

Organizations using PaperCut NG or MF are urged to apply the latest patches immediately and monitor for signs of unauthorized access. The ongoing exploitation of these vulnerabilities highlights the risks associated with unpatched systems and the need for continuous threat monitoring.



About Author

en_USEnglish