Back to feed

PaperCut zero-days patched last week now exploited in data theft attacks

2 min
PaperCut zero-days patched last week now exploited in data theft attacks

This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers are exploiting two recently patched PaperCut vulnerabilities to steal data from print management servers. The flaws, CVE-2026-81578 and CVE-2026-82078, allow authentication bypass and remote code execution. PaperCut Software released emergency patches on Thursday and Friday, but data theft attacks are already underway.

Key Facts

  • PaperCut NG and MF are used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
  • The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut servers.
  • PaperCut Software released two sets of emergency patches on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks.
  • Threat intelligence company Defused confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.
  • Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online.

Exploitation Details

Defused observed exploit activity for CVE-2026-81578 and CVE-2026-82078 in its honeypots since late August 29 UTC. An actor is abusing the authentication bypass to hijack PaperCut's external user-lookup. Unlike the remote code execution path in public writeups, the actor goes for data theft by dumping database tables via Derby. PaperCut Software has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.

Historical Context

Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years. A critical remote code execution vulnerability CVE-2023-27350 and a high-severity information disclosure flaw CVE-2023-27351 were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs. Microsoft revealed two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the attacks. In May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting CVE-2023-27350 for initial access to targets' networks. CISA flagged another remote code execution vulnerability CVE-2023-2533 as actively exploited in July 2025.

1 source

Time · lag behind first