← Back to overview

Two recently patched security vulnerabilities in PaperCut NG and MF print management software are being actively exploited in data theft attacks. The vulnerabilities were initially exploited as zero-days before patches were released. Attackers are leveraging these flaws to steal data from affected organizations. PaperCut is widely used print management software deployed across enterprises and educational institutions. The exploitation occurred shortly after patches were made available, indicating rapid weaponization by threat actors. Organizations using PaperCut NG or MF are strongly advised to apply the available patches immediately. The active exploitation underscores the risk of delayed patching for critical software vulnerabilities.

Technical details

Two zero-day vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in PaperCut NG and MF print management software can be chained to bypass authentication and achieve remote code execution (RCE) on vulnerable servers. Threat intelligence firm Defused observed active exploitation beginning August 29, 2026 UTC via honeypots. Attackers are abusing the authentication bypass to hijack PaperCut's external user-lookup mechanism and exfiltrate data by dumping database tables via Apache Derby (embedded DB), rather than pursuing the RCE path described in public writeups. PaperCut Software released two sets of emergency patches on consecutive days (Thursday and Friday) and published indicators of compromise. Over 800 PaperCut MF and NG servers are currently exposed on the internet according to Shadowserver. Historically, similar PaperCut flaws (CVE-2023-27350 and CVE-2023-27351) were chained in 2023 attacks by LockBit, Clop, Muddywater, APT35, and Bl00dy ransomware gangs, with attackers abusing the Print Archiving feature to capture documents.

Mitigation steps

1. Apply the two emergency patches released by PaperCut Software on Thursday and Friday (August 2026) immediately to all PaperCut NG and MF servers. 2. Review PaperCut's published indicators of compromise (IOCs) and apply recommended blocking measures. 3. Restrict internet exposure of PaperCut servers; take them off public internet access where possible (Shadowserver shows 800+ exposed servers). 4. Monitor PaperCut servers for signs of authentication bypass, unusual external user-lookup activity, and Derby database access or data dumping. 5. Audit PaperCut server logs for suspicious activity since at least August 29, 2026. 6. Review and restrict access to the Print Archiving feature to minimize document exposure risk. 7. Follow CISA and FBI advisories for additional guidance on PaperCut-related threats.

Affected products

  • PaperCut MF (all versions prior to emergency patches released August 2026)
  • PaperCut NG (all versions prior to emergency patches released August 2026)

Related CVE's

  • CVE-2023-2533
  • CVE-2023-27350
  • CVE-2023-27351
  • CVE-2026-81578
  • CVE-2026-82078

Related threat actors

  • APT35
  • Bl00dy Ransomware Gang
  • Clop
  • LockBit
  • Muddywater

IOC's

Exploitation of PaperCut external user-lookup mechanism, Derby database table dumping activity on PaperCut servers, Authentication bypass attempts on PaperCut NG/MF servers, Indicators of compromise published by PaperCut at: https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#indicators-of-compromise-and-investigation-guidance

Categories

  • Data Breach & Exfiltration
  • Enterprise Applications
  • Ransomware & Malware
  • Zero-Day Vulnerabilities

Related links