Attackers are exploiting two recently patched PaperCut zero-days to steal data from vulnerable PaperCut NG and MF print management servers.
The flaws, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and achieve remote code execution. PaperCut issued several emergency patches after learning that attackers had already used the vulnerabilities as zero-days.
Attackers target databases instead of remote code execution
Threat intelligence firm Defused reported exploit activity in its honeypots from late 29 August. It said one threat actor was abusing the authentication bypass to take control of PaperCut’s external user-lookup feature.
Rather than following the remote code execution route described in public research, the actor appears to be focused on data theft. Defused said the attacks dump database tables through Derby, the database technology used by PaperCut.
PaperCut has not publicly linked the activity to a specific threat group or detailed what attackers do after they compromise affected systems. However, it has released indicators of compromise to help organisations investigate and block the attacks.
PaperCut urges immediate update for exposed servers
PaperCut released three emergency updates across Thursday, Friday and Tuesday. The first update provided an urgent mitigation, while later releases added further hardening as the company learned more about the attacks.
The company urged all customers with internet-facing PaperCut Application Servers to install Emergency Patch Release 3 as soon as possible. This applies even to organisations that had already installed an earlier emergency update.
PaperCut said more emergency releases could follow if needed before it delivers a fully tested official release.
More than 800 PaperCut servers remain exposed
PaperCut says its software supports 100 million users across more than 70,000 organisations, including businesses, government agencies and educational institutions.
Shadowserver currently tracks more than 800 PaperCut NG and MF servers exposed to the internet. It is unclear how many of those systems are honeypots or have already received security updates.
PaperCut flaws have repeatedly attracted both ransomware operators and state-backed groups. In 2023, LockBit and Clop exploited chained PaperCut vulnerabilities, while Iranian-linked MuddyWater and APT35 actors also joined the attack wave.
The FBI and CISA later warned that the Bl00dy Ransomware gang was using a PaperCut remote code execution flaw for initial access. CISA also added another actively exploited PaperCut vulnerability to its Known Exploited Vulnerabilities catalogue in July 2025.


0 responses to “PaperCut Zero-Days Used in Data Theft Attacks”