PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog. Attackers are now using these flaws to conduct data theft and hands-on-keyboard intrusions. These vulnerabilities affect all versions of PaperCut NG and MF print management software. While patches were released last week, active exploitation continues as hackers move beyond automated scripts to manual system manipulation.
What changed
CISA officially cataloged the vulnerabilities as actively exploited while reports emerged of data theft and manual intrusions.
Live updates
-
CISA Adds PaperCut Zero-Days to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog. Attackers are now using these flaws to conduct data theft and hands-on-keyboard intrusions. These vulnerabilities affect all versions of PaperCut NG and MF print management software. While patches were released last week, active exploitation continues as hackers move beyond automated scripts to manual system manipulation.
Why it matters
These vulnerabilities allow attackers to bypass authentication and execute remote code. A Metasploit module has lowered the barrier for entry, leaving nearly half of tracked installations exposed.
What is confirmed
- CISA added PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog.
- Attackers are using CVE-2026-81578 and CVE-2026-82078 to steal data.
Still unconfirmed
- Hackers are performing hands-on-keyboard activity during PaperCut attacks.
What to watch next
- Updates on the percentage of installations patched since the CISA warning
- Reports of specific organizations targeted for data theft
confidence 100%Sources used for this update (4)
- securityaffairs.com — U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
- www.securityweek.com — PaperCut Exploitation Escalates to Active Intrusions
- www.bleepingcomputer.com — Recently patched PaperCut zero-days used in data theft attacks
- cyberpress.org — CISA Warns of Two PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks
-
PaperCut Zero-Day Chain Exploited via Metasploit as 47% of Servers Remain Unpatched
Attackers are using a chain of zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and execute remote code on PaperCut NG and MF servers. A new Metasploit Framework module created by Stephen Fewer makes these exploits more accessible. Despite two emergency patches, 47% of tracked installations remain vulnerable. Compromised internet-facing servers are being loaded with legitimate remote access software to maintain persistence. PaperCut confirmed customer incidents shortly before the Metasploit module was submitted.
Why it matters
The vulnerabilities affect all versions of the print management software. This follows a 2023 wave of attacks that specifically targeted higher education customers. The current exploit chain allows unauthenticated access to critical server functions.
What is confirmed
- The exploited vulnerabilities are identified as CVE-2026-82078 and CVE-2026-81578.
- The vulnerability chain combines authentication bypass with remote code execution.
- PaperCut has released a second emergency patch for these flaws.
- Stephen Fewer submitted pull request #21842 to the Metasploit Framework to target the PaperCut zero-day chain.
Still unconfirmed
- 47% of tracked PaperCut installations are still running unpatched versions.
- Threat actors are installing legitimate remote access software on compromised internet-facing servers.
What to watch next
- Confirmation of specific industries currently being targeted.
confidence 90%Sources used for this update (5)
- securityaffairs.com — Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
- www.securityweek.com — More Details Emerge on Exploited PaperCut Vulnerabilities
- www.cybersecuritydive.com — PaperCut issues emergency patches as threat actors target chained vulnerabilities
- cyberpress.org — Metasploit Exploit Targets Actively Exploited PaperCut NG/MF Zero-Day RCE Chain
- www.helpnetsecurity.com — Attackers plant remote access tools on compromised PaperCut servers
-
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
Attackers are exploiting a zero-day vulnerability in PaperCut, affecting all NG and MF versions. The vulnerability allows for code execution without authentication. PaperCut has released emergency patches to address the issue. Multiple sources confirm the exploitation and patch releases.
Why it matters
The exploitation of the PaperCut zero-day vulnerability highlights the ongoing threat of unpatched software vulnerabilities being targeted by attackers. PaperCut is a popular print management software used in various organizations. The vulnerability's exploitation could lead to unauthorized access and potential data breaches. This incident emphasizes the importance of timely patching and software updates.
What is confirmed
- The zero-day vulnerability affects all PaperCut NG and MF versions.
- Attackers can chain two PaperCut flaws to execute code without authentication.
- PaperCut has released emergency patches to address the exploited zero-day vulnerability.
- Multiple sources confirm the exploitation of the PaperCut zero-day vulnerability.
What to watch next
- Further updates on the impact of the vulnerability on specific organizations
- Releases of additional patches or updates by PaperCut
- Investigations into the attackers' motives and identities
confidence 100%Sources used for this update (5)
- The Hacker News — PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
- The Hacker News — Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
- SecurityWeek — PaperCut Releases Emergency Patch for Exploited Zero-Day
- Printweek — PaperCut targeted by hackers
- BleepingComputer — PaperCut releases second emergency patch for exploited flaws