PaperCut Exploitation Escalates to Active Intrusions

A growing number of organizations are falling victim to a sophisticated cyber attack campaign that exploits two vulnerabilities in PaperCut’s print management solutions, NG and MF. Threat actors have shifted from reconnaissance to hands-on-keyboard activity, compromising vulnerable systems and deploying remote access tools.

PaperCut first issued warnings about an actively exploited zero-day vulnerability on August 27, but it soon became apparent that attackers were chaining two separate flaws to gain unauthorized access. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, can be exploited by unauthenticated attackers to bypass authentication and execute arbitrary code on affected PaperCut instances.

The vendor has since released emergency patches for the vulnerabilities, but attacks are escalating at an alarming rate. According to WatchTowr, a firm that monitors exposure management, activity has evolved quickly from exploratory probes to real-world exploitation accompanied by human interaction. Threat actors are demonstrating “above average” sophistication in their attacks, with some designed to facilitate external network pivoting and continue attacks.

The deployment of remote access tools on targeted systems is also being seen as attackers gain access to compromised hosts. This behavior is consistent with initial access brokers and other aggressive operators. PaperCut has updated its indicators of compromise (IoCs) to reflect the escalating threat, specifically highlighting the use of remote access tools.

It’s estimated that over 1,000 PaperCut NG/MF instances are exposed to the internet, making them vulnerable to exploitation. Federal agencies have been instructed to address the flaws by September 14, and CISA has added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. If your organization is running an unpatched PaperCut instance, it’s essential to assume that you’re already compromised.

“The situation is dire,” warns Jake Knott, head of threat intelligence at WatchTowr. “If exposed to the internet and unpatched at any stage in the last few days, systems should be assumed compromised by an active attacker who is combing through vulnerable hosts looking for interesting or valuable targets.” If you haven’t already, now is the time to trigger incident response processes and patch your PaperCut instances as soon as possible.


Source: SecurityWeek — 2026-09-01