PaperCut has confirmed active exploitation of an undisclosed zero-day affecting all versions of its PaperCut NG and MF print-management products. The attacks target publicly accessible PaperCut Application Servers, and the vendor has reported customer incidents but has not disclosed the flaw’s technical details, attacker attribution, post-compromise actions, or whether data was stolen.
PaperCut released emergency patches for public-facing Application Servers and urged customers to immediately restrict the web interface to trusted IP addresses using firewall or network controls. Administrators should investigate alerts involving suspicious pc-app.exe activity, altered or missing server.log files, and anomalous log errors; however, PaperCut cautioned that the absence of these indicators does not confirm a system is uncompromised. The incident follows prior ransomware and state-linked exploitation of PaperCut flaws, including CVE-2023-27350 and CVE-2023-27351.

See which actors are running it and whether you're in range.
21 events from the most recent confirmed update back to the earliest known activity.
On August 31, 2026, CISA added actively exploited PaperCut NG/MF flaws CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities Catalog. CISA required U.S. federal civilian executive-branch agencies to remediate them by September 14, while noting ransomware use was unknown.
On August 30, 2026, PaperCut expanded its compromise indicators to include attackers installing SimpleHelp from C:\ProgramData and using AnyDesk as a redundant remote-access channel. It identified a potential SimpleHelp indicator as a "Remote Access Service" Windows service running SimpleService.exe from the JWrapper-Remote Access directory.
Beginning around August 29, 2026, Defused observed an actor exploiting CVE-2026-81578 and CVE-2026-82078 in honeypots. The actor hijacked PaperCut's external user-lookup capability and dumped database tables through Derby, indicating data theft rather than use of the publicly described RCE path.
PaperCut's CVE record for CVE-2026-81578 described a high-severity authentication-bypass flaw in the PaperCut NG/MF web management interface that can let unauthenticated requests trigger backend administrative actions before validation. The record assigned CVSS 4.0 score 8.8 and identified versions 24.1.10, 25.0.13, and 26.0.5 as fixed thresholds.
PaperCut published the CVE record for CVE-2026-82078, a critical unsafe dynamic class-loading flaw in PaperCut NG and MF database connection utilities. The record lists versions 24.1.10, 25.0.13, and 26.0.5 as fixed releases and assigns a CVSS v4.0 score of 9.4.
PaperCut issued Emergency Patch Release 2 as part of its 27 August urgent security advisory, following reported problems with the prior emergency security update.
PaperCut released emergency patches for public-facing NG/MF Application Servers and urged customers to restrict web-interface access to trusted IP addresses. It also published compromise indicators including suspicious pc-app.exe activity, altered or missing server.log files, and two specified log errors, while stating that further IOCs and remediation guidance would follow.
On 2026-08-27, PaperCut issued an urgent security bulletin warning that an undisclosed vulnerability affecting PaperCut NG and PaperCut MF, including all versions according to the company, was being actively exploited against internet-exposed Application Servers. PaperCut confirmed customer incidents and said it reproduced the issue using information from a university customer’s security team.
Exploitation attempts targeting PaperCut NG and MF zero days were first observed on August 26, 2026. Recovered payloads focused on system discovery, with investigators reporting no identified persistence, secondary malware, or command-and-control traffic at that time.
In May 2023, CISA and the FBI warned that the Bl00dy Ransomware Gang was exploiting vulnerable PaperCut servers against education-sector organizations.
In April 2023, attackers exploited the critical PaperCut flaw CVE-2023-27350, which enabled authentication bypass and remote code execution. Microsoft linked some activity to Clop and observed intrusions leading to LockBit ransomware; Iranian state-backed groups also exploited the vulnerability.
Rapid7 confirmed that multiple customers were compromised through CVE-2026-81578 and CVE-2026-82078. It observed attackers deploying their own remote-management tools on compromised hosts to maintain persistence, elevate privileges, and attempt lateral movement.
Shadowserver identified more than 800 internet-exposed PaperCut NG and MF servers. The report did not establish how many of those systems remained unpatched, were vulnerable, or were honeypots.
PaperCut made Patch 3 available for an unspecified security issue affecting PaperCut NG and MF. The company said it released updates incrementally as they became available rather than waiting for a single comprehensive patch release.
WatchTowr reported that PaperCut exploitation had progressed from reconnaissance to interactive, hands-on-keyboard activity. The observed operators deployed access-controlled in-memory payloads and performed activity supporting pivots from exposed PaperCut servers into internal networks, behavior assessed as consistent with initial-access brokers.
CSIRT Italia described CVE-2026-82078 as an unsafe-reflection issue in configurable Java class-loading parameters that can instantiate arbitrary classpath classes and execute code in the PaperCut process. It described CVE-2026-81578 as an unauthenticated web-administration access-control bypass that can allow configuration changes before authentication completes.
Huntress reported that approximately 47% of roughly 2,500 tracked PaperCut installations were running version 23 or earlier, for which no patch was available. Fixes for version 24 were still under development, and a version 24 server was reportedly attacked before a fix became available.
watchTowr reported multiple patch bypasses and an additional authentication-bypass vulnerability affecting PaperCut NG and MF. PaperCut's second emergency patch remediated one identified bypass, but watchTowr said further bypasses affect the latest fully patched version.
Researchers detailed an authentication-bypass chain exploiting PaperCut's Apache Tapestry direct-request handling to invoke privileged ConfigEditor and UserList components without authentication. Attackers can modify external database-lookup settings and trigger malicious SQL through a forged user search, ultimately using JavaScript-backed database triggers to execute operating-system processes.
Huntress observed exploitation in two customer environments, including reconnaissance commands and a self-deleting Java payload that deleted PaperCut logs. It independently reproduced a pre-authentication exploit chain against an unpatched PaperCut NG installation that achieved Windows SYSTEM-level code execution.
The actively exploited PaperCut NG and MF vulnerabilities were identified as CVE-2026-82078 and CVE-2026-81578, both rated above 8.8 in severity. PaperCut had previously described the actively exploited issue without disclosing vulnerability identifiers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
50 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesocprime.com
Open sourcehorizon3.ai
Open sourcereddit.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcereddit.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.