Cybersecurity

PaperCut Vulnerabilities Exploited as “Zero-Days” Turn into a Data Theft Tool

Attackers have begun exploiting two vulnerabilities in PaperCut NG and MF, after they were patched last week, to bypass authentication, remotely access print management servers, and extract tables from victims’ databases.

2026-09-01
4 min read
12 views
فريق تحرير certi.news
PaperCut Vulnerabilities Exploited as “Zero-Days” Turn into a Data Theft Tool

Attackers are exploiting two security vulnerabilities in PaperCut NG and PaperCut MF print management software to conduct data theft attacks, after the company issued emergency patches to address them last week following the discovery that they were being exploited as “zero-day” attacks.

The vulnerabilities are tracked as CVE-2026-81578 and CVE-2026-82078, and can be chained together to bypass authentication and execute code remotely on unprotected PaperCut NG and MF servers. PaperCut Software issued two sets of emergency updates on Thursday and Friday, and also published indicators of compromise to help defense teams detect and block the ongoing activity.

Activity Targets Data, Not Just Code Execution

Threat intelligence company Defused confirmed over the weekend that it had observed exploitation of the two vulnerabilities in honeypot environments since late August 29 in Coordinated Universal Time. According to the company, one attacker is exploiting the authentication-bypass path to hijack PaperCut’s external-user search function.

Rather than following the remote-code-execution path described in public reports, the attacker used the function to access data and extract database tables through Derby. PaperCut has not yet attributed the attacks to a specific actor, nor has it explained what the attackers do after compromising the servers.

Scope of Exposure Remains Unclear

PaperCut Software says its products are used by 100 million users across more than 70,000 organizations, including large companies, government agencies, and educational institutions. Shadowserver, which tracks system exposure, is monitoring more than 800 PaperCut MF and NG servers exposed to the internet.

However, this figure does not indicate how many servers are honeypots, which have received the updates, or which have already been compromised. It therefore does not, by itself, provide an estimate of the scale of the damage, but it shows that internet-connected servers still represent an observable and exploitable exposure surface.

Why Does This Matter?

The practical risk is not limited to the possibility of technical control over a print server; the observed activity shows that attackers are using the vulnerability to access data stored in the system database. This expands the impact of the incident from disrupting printing services or executing commands to the potential exposure of user information, print records, and associated data, based only on what Defused’s activity demonstrates.

PaperCut’s widespread use within companies, government agencies, and educational institutions also makes affected servers an important part of the operational infrastructure of multiple organizations. Based on the available information, the immediate priority for user organizations is to apply the emergency patches issued by PaperCut and review the indicators of compromise it published, while noting that the source does not establish the number of victims or the type of data stolen in the confirmed attacks.

A Previous History of Exploitation

The new campaign joins a recurring history of targeting PaperCut. In April 2023, a high-severity remote-code-execution vulnerability tracked as CVE-2023-27350 was exploited alongside an information-disclosure vulnerability, CVE-2023-27351, and the attacks were linked at the time to the LockBit and Clop gangs. Two weeks later, Microsoft said that the Iran-backed Muddywater and APT35 groups had joined the activity.

In May 2023, the FBI and CISA warned that the Bl00dy gang was exploiting CVE-2023-27350 for initial access to targeted networks, while CISA added another remote-code-execution vulnerability, CVE-2023-2533, to its catalog of vulnerabilities actively exploited in July 2025.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news