Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.
PaperCut Software released two sets of emergency patches to address the vulnerabilities on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks. However, the company has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.
Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims’ servers.
“We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),” Defused said. “An actor is abusing the auth bypass to hijack PaperCut’s external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft – dumping DB tables via Derby.”
Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks.
Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years.
A critical remote code execution vulnerability (CVE-2023-27350) and a high-severity information disclosure flaw (CVE-2023-27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.
Microsoft revealed two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the attacks.
As the company explained at the time, the threat groups abused the ‘Print Archiving’ feature designed to save all documents sent through PaperCut printing servers.
One month later, in May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023-27350 flaw for initial access to targets’ networks.
The Cybersecurity and Infrastructure Security Agency (CISA) flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
PaperCut releases second emergency patch for exploited flaws
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Metabase SQLi zero-day exploited in customer data-theft attacks
Berlin confirms data theft after Rhysida ransomware attack claims
Over 8,300 Gitea servers vulnerable to code execution attacks
Microsoft Exchange Online outage causes email failures, auth issues
Anthropic is cutting Claude Code’s current weekly limits by 17%
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Overdue a password health-check? Audit your Active Directory for free
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Learn how ESET MDR can enhance your organization’s security posture
AI-driven vulnerability discovery is accelerating. See how Action1 helps remediation keep pace.
Identity, Data Governance & Threat Detection in One Platform: Take our In-Browser Tour
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



