Active exploitation of two newly patched PaperCut vulnerability flaws—tracked as CVE-2026-81578 and CVE-2026-82078—has escalated into direct data theft attacks targeting exposed print management servers. Threat actors are actively abusing these security flaws in PaperCut NG and PaperCut MF software to bypass administrative authentication and dump internal database contents. While public analysis originally highlighted a full remote code execution (RCE) chain, operational telemetry reveals that attackers are taking a stealthier path: abusing the authentication bypass to hijack external user-lookup routines and extract database tables directly.
PaperCut software serves over 100 million users across more than 70,000 organizations, including enterprise networks, state agencies, and educational institutions. Internet telemetry from Shadowserver currently identifies over 800 PaperCut MF and NG application servers exposed directly to the public internet, placing unpatched deployments at immediate risk of compromise.
Exploit Mechanics: From Auth Bypass to Database Extraction
The vulnerability pair consists of an authentication bypass (CVE-2026-81578) and a chained execution flaw (CVE-2026-82078). When combined, they allow unauthenticated network attackers to obtain full control over vulnerable PaperCut NG and PaperCut MF instances.
However, live threat intelligence captured from honeypot deployments indicates that attackers are pivoting away from standard shell-spawning RCE routines. Threat intelligence firm Defused reported active exploit traffic starting late UTC on August 29, observing adversaries using the authentication bypass to target PaperCut’s external user-lookup functionality.
Instead of dropping web shells or executing OS-level commands, adversaries are leveraging this component to exfiltrate database records from PaperCut’s embedded Apache Derby database engine. Print management databases contain rich organizational context, including system user accounts, directory synchronization settings, internal domain structure details, and print job logs. Exfiltrating this data via embedded SQL functionality allows attackers to acquire valuable administrative and user intelligence while generating significantly less noise than traditional post-exploitation command execution.
The Blast Radius of Compromised Print Infrastructure
Print management software sits at a sensitive intersection within enterprise architecture. To facilitate centralized printing, quota management, and single sign-on across multi-function printers (MFPs), PaperCut Application Servers integrate directly with core identity providers such as Active Directory and LDAP servers.
When an attacker gains unauthenticated access to a PaperCut server, the blast radius extends far beyond print queues:
- Identity & Credential Harvest: Embedded databases store synced user accounts, administrative configurations, and active directory lookup hooks. Access to these tables provides adversaries with target lists for credential stuffing, spear-phishing, or lateral movement.
- Sensitive Document Access: Feature sets within print management platforms—such as document archiving and print job logs—often hold full document captures, sensitive metadata, or plain-text document content sent to corporate printers.
- Network Foothold: Because PaperCut servers frequently reside on internal management subnets while maintaining inbound access for remote users, a compromised instance acts as an ideal pivot point into restricted internal network zones.
A Persistent Target for Cybercrime and Nation-State Actors
Centralized print servers have become primary targets for threat actors seeking initial access and rapid domain enumeration. PaperCut vulnerabilities have a documented history of rapid weaponization by diverse threat groups:
- Ransomware Syndicates: In April 2023, critical vulnerabilities CVE-2023-27350 and CVE-2023-27351 were chained in widespread campaigns conducted by the LockBit and Clop ransomware gangs. The Bl00dy Ransomware group similarly adopted CVE-2023-27350 for network intrusion shortly thereafter in May 2023.
- State-Sponsored Intrusion Sets: Iranian APT groups, including Muddywater and APT35, joined the 2023 PaperCut exploitation wave within weeks of public disclosure, specifically targeting the application’s “Print Archiving” feature to exfiltrate internal corporate communications.
- Continued Vulnerability Target: CISA previously flagged another high-severity PaperCut RCE vulnerability (CVE-2023-2533) as actively exploited in July 2025.
The immediate pivot to data theft in the current campaign demonstrates that threat actors are continuously refining their post-exploitation tactics to maximize exfiltration speed before organizations complete patch rollouts.
Remediation and Response Guidance
PaperCut Software has issued three emergency mitigation patches in rapid succession—Thursday, Friday, and Tuesday—to protect deployments that cannot immediately be taken offline. CEO Chris Dance noted that while these emergency releases rush hardening fixes to exposed systems, a fully QA-tested official release will follow.
Organizations running PaperCut NG or PaperCut MF should immediately take the following actions:
- Apply Emergency Patch Release 3 Immediately: All organizations operating internet-facing PaperCut Application Servers must update to Emergency Patch Release 3 immediately. PaperCut explicitly advises that Release 3 must be applied even if Release 1 or Release 2 has already been installed.
- Remove Public Internet Exposure: Place PaperCut management interfaces behind an enterprise VPN, Zero Trust Network Access (ZTNA) solution, or restricted internal network segment. Application servers should never be directly exposed to the open internet.
- Audit Database Activity & Derby Logs: Inspect Apache Derby database query logs and network traffic for unusual queries targeting the external user-lookup component, specifically looking for bulk data export commands or anomalous database table dumps originating after August 29.
- Ingest Vendor Indicators of Compromise: Review and deploy the indicators of compromise (IOCs) released by PaperCut across SIEM and network detection tools to hunt for past unauthorized access attempts or suspicious administrative session creations.
Related content
PaperCut NG/MF Critical Vulnerability CVE-2026-81578 Exposes Systems to Takeover
AdvisoryPaperCut NG/MF Unsafe Reflection Vulnerability (CVE-2026-82078) Analysis
Security NewsUK ACRO Criminal Records Office Reprimanded After Unpatched CMS Led to Two-Year Breach
Security NewsAdobe Patches Maximum-Severity CVSS 10.0 Zero-Click Flaw in Campaign Classic
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call