A devastating new wave of cyberattacks has emerged, exploiting two recently patched vulnerabilities in the PaperCut print management software used by millions worldwide. The security flaws, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and grant attackers remote code execution on vulnerable servers. This has led to a surge in data theft attacks, with threat actors using these exploits to steal sensitive information from victims’ systems.
PaperCut Software’s emergency patches released last week have been met with a swift response from attackers, who are now exploiting the vulnerabilities in real-world attacks. According to Defuse, a leading threat intelligence company, they have observed exploit activity since August 29th, with attackers using the auth bypass to hijack PaperCut’s external user-lookup and dump database tables via Derby.
The scope of this issue is significant: over 100 million users across more than 70,000 organizations are potentially at risk, including large companies, state agencies, and educational institutions. This includes a substantial number of servers exposed online, according to Shadowserver, which tracks over 800 PaperCut MF and NG servers that have not been patched or secured against these attacks.
This is not the first time PaperCut security flaws have been exploited in the wild. In April 2023, critical remote code execution and information disclosure vulnerabilities were chained by ransomware gangs, including LockBit and Clop, as well as state-backed hacking groups Muddywater and APT35. These groups abused the Print Archiving feature designed to save all documents sent through PaperCut printing servers.
The prevalence of these attacks highlights a disturbing trend in the world of cybersecurity: once attackers have gained initial access using valid credentials, prevention scores plummet, with only 37% of actions being blocked. This underscores the importance of proactive security measures and emphasizes the need for organizations to prioritize patch management, regular vulnerability scanning, and robust incident response planning.
For users of PaperCut software, it’s essential to act quickly: if you haven’t already, apply the latest emergency patches as soon as possible. Additionally, remain vigilant and monitor your systems closely for signs of compromise. In the long run, this incident serves as a stark reminder that even after vulnerabilities are patched, attackers will continue to exploit them – making ongoing security awareness and preparedness crucial in today’s threat landscape.
Source: Bleeping Computer — 2026-09-01