A critical vulnerability in PaperCut print management software has been exploited by attackers to steal sensitive information from thousands of organizations worldwide. The two zero-day vulnerabilities, which were patched just last week, have allowed hackers to bypass authentication and gain remote access to vulnerable servers.
PaperCut Software’s software is used by a staggering 100 million users across more than 70,000 organizations, including large corporations, government agencies, and educational institutions. This means that the potential impact of these attacks could be vast, with sensitive data compromised in numerous sectors.
The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and grant remote code execution on vulnerable PaperCut NG and MF print management servers. In other words, hackers have found a way to gain unauthorized access to these systems and execute malicious code with ease.
Fortunately, PaperCut Software acted swiftly in response to the discovery of these vulnerabilities, releasing two sets of emergency patches last Thursday and Friday. The company also published indicators of compromise (IoCs) to help defenders block ongoing attacks. However, despite these efforts, it’s clear that some attackers have already begun exploiting these flaws in the wild.
According to threat intelligence firm Defused, their honeypots have detected exploit activity related to CVE-2026-81578 and CVE-2026-82078 since late last week. What’s concerning is that the attackers are not attempting to gain remote code execution, but rather using the vulnerabilities to steal data from victims’ servers.
This raises concerns about the potential for sensitive information to be compromised in these attacks. With thousands of PaperCut MF and NG servers exposed online, it’s likely that many organizations have fallen victim to these exploits. As we’ve seen before, state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws with devastating results.
It’s essential for organizations using PaperCut software to take immediate action to patch their systems and review their security posture. This includes reviewing network logs for any suspicious activity and updating credentials where necessary. Regular security audits and vulnerability assessments can also help identify potential weaknesses in the system before they’re exploited by attackers.
In conclusion, the recent exploitation of PaperCut vulnerabilities serves as a stark reminder of the importance of robust cybersecurity measures in today’s threat landscape. With thousands of organizations at risk, it’s crucial that we prioritize patching and security awareness to prevent further breaches and data theft.
Source: Bleeping Computer — 2026-09-01