Skip to main content
Emerging ThreatsMalware & Ransomware

PaperCut Zero-Days Exploited in Data Theft Attacks

Rows of computer servers and network equipment in a brightly-lit office server room.
"We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th)," Defused said.

CVE-2026-81578 and CVE-2026-82078: a chained bypass to remote code execution

Two vulnerabilities in PaperCut NG and MF, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and achieve remote code execution on vulnerable PaperCut print management servers. PaperCut Software confirmed the flaws were being exploited as zero-days and issued emergency patches to address them.

Observed attacks: data theft, not (only) RCE demonstrations

Over the weekend, threat intelligence company Defused confirmed attackers are using the two flaws in the wild to steal data. Defused reported the actor is abusing the authentication bypass to "hijack PaperCut's external user-lookup" and, rather than following the RCE paths found in public writeups, is "going for data theft - dumping DB tables via Derby." That behavior points to immediate data-exfiltration activity on compromised servers.

PaperCut's emergency response and remaining questions

PaperCut Software released two sets of emergency patches on Thursday and Friday and published indicators of compromise intended to help defenders block ongoing attacks. The company said the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions. PaperCut has not attributed the attacks and has not explained what the threat actors are doing after gaining access to vulnerable servers.

How many servers remain exposed: Shadowserver's snapshot

Internet security watchdog Shadowserver currently tracks more than 800 PaperCut MF and NG servers exposed online. Shadowserver's count does not distinguish between honeypots and live, vulnerable instances; Defused explicitly referenced honeypots in its observations. That mix means defenders must assume a nontrivial population of reachable servers could still be susceptible until patches are verified and indicators of compromise are applied.

Past exploitation of PaperCut flaws: a pattern of interest to defenders and policymakers

PaperCut has been targeted repeatedly in recent years. In April 2023, a critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in attacks linked to the LockBit and Clop ransomware gangs. Microsoft later said the Muddywater and APT35 Iranian state-backed groups also participated in those attacks. Those adversaries abused PaperCut's "Print Archiving" feature, which saves documents sent through PaperCut printing servers.

One month later the FBI and CISA warned that the Bl00dy Ransomware gang had begun exploiting CVE–2023–27350 for initial access. CISA also flagged another remote code execution vulnerability, CVE-2023-2533, as actively exploited in July 2025. The recent CVE-2026-81578 / CVE-2026-82078 activity joins a record in which both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild.

What this means for security teams, affected organizations, and regulators

  • Technologists and security teams: The immediate priority is deployment of the emergency patches released by PaperCut on Thursday and Friday and application of the company's indicators of compromise. Defused's report that attackers are dumping Derby database tables highlights the need to inspect PaperCut databases and logs for evidence of data extraction.
  • Affected enterprises and procurement leaders: With PaperCut used by 100 million users in over 70,000 organizations, large organizations, state agencies, and educational institutions should inventory PaperCut NG and MF instances, confirm exposure status against Shadowserver's visibility, and validate that emergency updates have been applied.
  • Policymakers and regulators: The history of both criminal and state-affiliated exploitation of PaperCut vulnerabilities — and prior warnings from the FBI and CISA — underscores why public alerts and coordinated disclosures remain central to reducing windows of exposure after zero-day exploitation is reported.

PaperCut's emergency patches and published indicators are immediate defensive tools, but two facts remain central: attackers have already adapted the two recent zero-days to steal data rather than merely demonstrate remote code execution, and the company has not yet described what compromised servers have had exfiltrated or who is responsible. Shadowserver's count of over 800 Internet-exposed PaperCut servers provides a concrete scale for response; whether defenders can close that gap quickly will determine how much additional data is at risk.

Original story