A pair of recently disclosed vulnerabilities affecting PaperCut NG and PaperCut MF has moved from an emerging security concern to an active intrusion threat, prompting security agencies and researchers to urge organizations to take immediate action.
The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, were added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog on August 31 after evidence showed that attackers were exploiting them in real-world attacks.
The development is particularly important for organizations running internet-accessible PaperCut application servers, which manage printing infrastructure across corporate, educational and other large environments.
From Scanning to Hands-On Intrusions
Security researchers initially observed attackers probing systems for weaknesses. The activity has since progressed toward what SecurityWeek describes as hands-on-keyboard operations, meaning attackers are no longer simply testing whether vulnerable systems can be reached but are actively interacting with compromised environments.
PaperCut has also issued an additional emergency patch after attackers reportedly found a way around an earlier fix. That progression highlights one of the more difficult realities of vulnerability management: patching a newly discovered flaw does not necessarily end the threat when attackers are already investigating ways around defensive measures.
Rapid7 says the vulnerabilities involve an authentication bypass that can allow attackers to invoke privileged PaperCut components and manipulate an external database lookup. A Metasploit module is also now available for security teams to validate exposure.
Why PaperCut Administrators Should Pay Attention
The urgency comes down to exposure.
Organizations that place PaperCut application servers directly on the internet provide attackers with a potentially valuable entry point. Once an attacker gains privileged access, the risk extends beyond the printing system itself. Compromised infrastructure can potentially be used for further reconnaissance, credential theft, persistence or movement into other parts of a corporate network.
CISA’s KEV designation is therefore more than another vulnerability listing. It signals that defenders should treat these flaws as actively exploited threats, rather than vulnerabilities that might eventually become dangerous.
PaperCut’s history also adds context. The platform was previously targeted by widespread exploitation of a different critical vulnerability in 2023, including attacks associated with ransomware groups.
The latest incident shows why organizations cannot rely solely on routine patch cycles for internet-facing infrastructure.
What Comes Next?
For administrators, the immediate priority is identifying vulnerable PaperCut systems, applying the appropriate emergency updates and reviewing systems for signs of compromise. Security teams should also pay attention to unusual authentication activity and unexpected changes involving PaperCut’s database configuration.
The absence of known malicious IP addresses or domains should not be treated as proof that an environment is safe. Rapid7 notes that PaperCut has not yet published validated network indicators, meaning organizations need to look beyond simple indicator-based detection.
The PaperCut case is another reminder that the most dangerous vulnerabilities are not necessarily the newest or most technically complex. Once attackers have a reliable path into widely deployed enterprise software, the window between disclosure and active exploitation can become extremely short.
For organizations running PaperCut NG or MF, the question is no longer whether these vulnerabilities could eventually be exploited. Evidence of exploitation means the priority now is determining whether an exposed system has already been targeted.
















Comments