ZeroHour
The Recordpublished ()ingested

PaperCut warns of hackers using printer management software flaw in attacks

highExploit / PoC exploited in the wildimportance 78CVE-2026-82078CVE-2026-81578
AI summary · glm-5.3-flash

PaperCut warns of active exploitation of CVE-2026-82078 and CVE-2026-81578 in NG/MF print management software used by universities, corporations, and governments.

PaperCut issued an emergency advisory saying vulnerabilities in PaperCut NG and MF, tracked as CVE-2026-82078 and CVE-2026-81578 with severity scores above 8.8, are under active exploitation with confirmed customer incidents. Huntress reported at least two customers impacted, and an initial patch was revised with input from Huntress and watchTowr researchers. PaperCut software is widely deployed at universities, corporations, and governments managing printers from Canon, Epson, Xerox, and Brother, and the vendor urged removing server web interfaces from the public internet. Previous PaperCut flaws were used by ransomware gangs like Bl00dy and Clop, and CISA has warned the education sector is particularly exposed.

  • CVE-2026-82078 and CVE-2026-81578 under active exploitation
  • Initial patch revised with Huntress and watchTowr input
  • Vendor urges removing PaperCut web interfaces from public internet
  • Historic ransomware abuse includes Bl00dy and Clop; schools exposed

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-82078
+1 in the same advisory: …81578
Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks

CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile).

Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578.

9.4
group max
2% KEV
  • PaperCut NG
  • PaperCut MF
mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant…
Full article454 words · extracted from therecord.media · click to collapse

The company behind a popular brand of printer management software warned customers of a new vulnerability currently being used by cybercriminals. 

PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation. The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578,  which both carry severity scores over 8.8 out of 10. 

“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the company said. 

PaperCut’s software is used widely across large organizations like universities, corporations and governments. Organizations use PaperCut software to manage a variety of printer brands including Canon, Epson, Xerox, Brother and more. 

The company urged customers to remove their servers from the public internet and restrict web access to only trusted IP addresses. Customers need to take every step to ensure PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. 

“Take this action now, even if you have not observed suspicious activity,” PaperCut said. 

In the security advisory issued on Thursday, the company said it used information provided by a university customer’s security team to reproduce the vulnerability and develop a fix. 

Multiple cybersecurity companies confirmed evidence of exploitation including Huntress, which said it has at least two customers impacted by the campaign targeting the bugs. 

An initial patch issued by PaperCut did not sufficiently address the vulnerabilities and the company said it worked with experts from Huntress and watchTwr to create a new patch released on Friday. 

Jake Knott, head of threat intelligence at watchTowr, noted that previous PaperCut vulnerabilities were used by ransomware gangs and opportunistic attackers to gain initial access. 

“PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated,” Knott said. 

In 2023, U.S. law enforcement agencies warned that ransomware gangs like Bl00dy and Clop were exploiting PaperCut bugs. The Cybersecurity and Infrastructure Security Agency (CISA) specifically issued an advisory for K-12 schools that said the education sector is particularly exposed to PaperCut vulnerabilities. 

Microsoft said an Iranian state-backed group known for attacking critical infrastructure exploited the same bug that year in multiple attacks.  

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities