PaperCut Exploitation Escalates to Active Intrusions

PaperCut Attacks Escalate to Active Intrusions, Threatening Thousands of Systems

A disturbing trend is unfolding in the cybersecurity world as attacks exploiting vulnerabilities in PaperCut’s print management solutions escalate from reconnaissance to active intrusions. The threat actors, who were initially using two recently discovered zero-day vulnerabilities to gain access to affected systems, have now moved on to hands-on-keyboard activity, compromising thousands of systems worldwide.

The two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, allow unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances. The vendor quickly rolled out emergency patches, but the attacks have continued unabated, with exposure management firm WatchTowr reporting a significant increase in activity.

According to Jake Knott, head of threat intelligence at WatchTowr, the attackers are now using their access to facilitate external-to-internal network pivoting and continue their attacks. This behavior is reflective of initial access brokers and other aggressive-outcome type operators. The deployment of remote access tools on targeted systems has also been observed, as indicated by PaperCut’s updated indicators of compromise (IoCs).

The cybersecurity agency CISA has added the two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, instructing federal agencies to address the flaws by September 14. With over 1,000 PaperCut NG/MF instances exposed to the internet, systems should be assumed compromised if they are unpatched and have been exposed to the Internet in the last few days.

The situation is dire, with WatchTowr’s Knott warning that patching alone will not lock out existing attackers. “If you haven’t already, now is the time to trigger incident response processes,” he emphasized. This means that affected organizations should assume they have been compromised and take immediate action to contain and remediate the situation.

The fact that these attacks are escalating so quickly highlights the importance of maintaining up-to-date security patches and having robust incident response plans in place. It also underscores the need for vendors like PaperCut to prioritize security and provide timely updates to their customers.

As we continue to navigate this complex cybersecurity landscape, it’s essential to stay vigilant and proactive. The takeaway from this story is clear: if your organization uses PaperCut NG/MF and has not patched the vulnerabilities, assume you have been compromised and take immediate action to protect your systems and data.


Source: SecurityWeek — 2026-09-01