Affected Systems
PaperCut NG and MF print management software, all versions prior to Emergency Patch Release 3 (issued September 2026). Affects internet-facing Application Servers. Used by 100 million users across 70,000+ organizations including enterprises, government agencies, and educational institutions. Over 800 servers currently exposed online.
Exploitation Status
Active exploitation confirmed since August 29, 2026. Attackers chaining CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) to steal data from vulnerable servers. Threat intelligence firm Defused observed exploit activity in honeypots targeting Derby database tables via hijacked external user-lookup feature. Threat actor attribution not yet disclosed by vendor.
Business Impact
High-severity incident affecting widely deployed print management infrastructure. Attackers can bypass authentication and execute arbitrary code on internet-facing PaperCut servers, leading to database exfiltration. PaperCut has history of exploitation by ransomware gangs (LockBit, Clop, Bl00dy) and state-sponsored groups (Muddywater, APT35). Organizations with exposed PaperCut servers face immediate risk of data breach. Emergency patches released in three iterations (Thursday, Friday, Tuesday) indicate evolving understanding of attack surface. CVSS scores not published.
Urgency
🔴 Immediate
Recommended Actions
- Apply PaperCut Emergency Patch Release 3 immediately to all NG and MF Application Servers, even if earlier emergency patches were installed
- Remove PaperCut Application Servers from direct internet exposure; place behind VPN or restrict access via firewall to trusted IP ranges only
- Review PaperCut-published indicators of compromise and search logs for authentication anomalies, external user-lookup abuse, and Derby database access patterns since August 29, 2026
- Audit PaperCut Print Archiving feature for unauthorized document access and review stored print jobs for sensitive data exposure
- Monitor for follow-on activity including lateral movement, credential harvesting, and ransomware deployment given historical targeting by LockBit, Clop, and state actors
