Recently patched PaperCut zero-days used in data theft attacks
Two patched PaperCut zero-days are now being abused in data theft attacks.
Summary
Two critical vulnerabilities in PaperCut NG and MF print management software, previously exploited as zero-days and recently patched, are now being actively abused for data theft. Attackers are chaining these flaws to bypass authentication, gain remote code execution, and dump database tables, specifically targeting data rather than just system compromise. PaperCut Software has released emergency patches and indicators of compromise, but the full scope and attribution of the ongoing attacks remain unclear.
Full text
Recently patched PaperCut zero-days used in data theft attacks By Sergiu Gatlan September 1, 2026 03:48 AM 0 Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers. PaperCut Software released two sets of emergency patches to address the vulnerabilities on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks. However, the company has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers. Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers. "We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said. "An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby." Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks. PaperCut servers exposed online (Shadowserver) Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years. A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs. Microsoft revealed two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the attacks. As the company explained at the time, the threat groups abused the 'Print Archiving' feature designed to save all documents sent through PaperCut printing servers. One month later, in May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting the CVE–2023–27350 flaw for initial access to targets' networks. The Cybersecurity and Infrastructure Security Agency (CISA) flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: PaperCut releases second emergency patch for exploited flawsPaperCut warns of NG, MF flaw exploited in zero-day attacksMetabase SQLi zero-day exploited in customer data-theft attacksBerlin confirms data theft after Rhysida ransomware attack claimsOver 8,300 Gitea servers vulnerable to code execution attacks
Indicators of Compromise
- cve — CVE-2026-81578
- cve — CVE-2026-82078