Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.
PaperCut Software released two sets of emergency patches to address the vulnerabilities on Thursday and Friday, and published indicators of compromise to help defenders block ongoing attacks. However, the company has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.
Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims’ servers.
“We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),” Defused said. “An actor is abusing the auth bypass to hijack PaperCut’s external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft – dumping DB tables via Derby.”
Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks.

Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years.
A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.
Microsoft revealed two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the attacks.
As the company explained at the time, the threat groups abused the ‘Print Archiving‘ feature designed to save all documents sent through PaperCut printing servers.
One month later, in May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting the CVE–2023–27350 flaw for initial access to targets’ networks.
The Cybersecurity and Infrastructure Security Agency (CISA) flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.



