Two security vulnerabilities in PaperCut NG and MF print management software are now being exploited in data theft attacks after being used as zero-days before patches were released. PaperCut says its software is used by 100 million people across more than 70,000 organizations, including businesses, government agencies and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the flaws can be chained to bypass authentication and achieve remote code execution on vulnerable PaperCut NG and MF servers.
PaperCut released emergency patches on Thursday and Friday and also published indicators of compromise to help defenders detect and block ongoing attacks. However, the company has not yet attributed the attacks or explained what attackers are doing after gaining access to vulnerable servers.
Threat intelligence company Defused confirmed over the weekend that attackers were actively abusing the vulnerabilities to steal data. The company said it observed exploitation activity in its honeypots beginning on August 29, with attackers using the authentication bypass to take control of PaperCut’s external user-lookup feature. Instead of following the publicly documented remote code execution route, the attackers were dumping database tables through Derby to steal information.
More than 800 PaperCut NG and MF servers are currently being tracked as exposed online by internet security watchdog Shadowserver. It is not known how many of those systems are honeypots or have already been secured against the attacks.
PaperCut has faced exploitation of its vulnerabilities before. In 2023, attackers chained CVE-2023-27350 and CVE-2023-27351 in attacks associated with the LockBit and Clop ransomware gangs. Iranian state-backed groups Muddywater and APT35 were also later linked to attacks exploiting PaperCut vulnerabilities.
Attackers previously abused PaperCut’s Print Archiving feature, which is designed to save documents sent through printing servers. In May 2023, the FBI and CISA also warned that the Bl00dy ransomware group had begun exploiting CVE-2023-27350 to gain initial access to victims’ networks.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
CISA later flagged another PaperCut remote code execution vulnerability, CVE-2023-2533, as actively exploited in attacks in July 2025.
PaperCut Zero-Day Flaws Exploited in Data Theft Attacks





