Recently patched PaperCut zero-days used in data theft attacks
Key Points:
- Two critical vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in PaperCut NG and MF print management software have been actively exploited for data theft shortly after emergency patches were released.
- PaperCut Software, used by 100 million users across over 70,000 organizations, issued three emergency patches within a week to address these flaws, urging customers with internet-facing servers to install the latest update immediately.
- The vulnerabilities allow attackers to bypass authentication and execute remote code, with recent attacks focusing on dumping database tables via Derby for data theft rather than remote code execution.
- Over 800 vulnerable PaperCut servers remain exposed online, and threat actors, including state-backed groups and ransomware gangs, have historically targeted PaperCut flaws for initial network access and data exfiltration.
- PaperCut continues to release emergency patches and has provided indicators of compromise to help defenders, though the specific threat actors behind the current attacks have not yet been identified.