Critical PaperCut Vulnerabilities Under Active Exploitation: Urgent Patching Required
**PaperCut**, a leading provider of print management software, has issued an urgent advisory regarding active exploitation of critical vulnerabilities in its **PaperCut NG** and **PaperCut MF** products. These bugs, identified as **CVE-2026-82078** and **CVE-2026-81578**, carry high severity scores and are being actively leveraged by cybercriminals. Organizations are strongly advised to patch immediately and restrict public internet access to their **PaperCut** servers.
The company behind the widely used print management software, **PaperCut**, has alerted its customers to a new set of vulnerabilities currently being exploited in the wild. An emergency advisory released Thursday evening confirmed active exploitation of these flaws in **PaperCut NG** and **PaperCut MF**.
### High-Severity Flaws Identified
**PaperCut** has released patches for the bugs, tracked as **CVE-2026-82078** and **CVE-2026-81578**, both of which have severity scores exceeding 8.8 out of 10. The company's security response team is actively investigating confirmed customer incidents and treating the matter with the highest priority.
### Widespread Use and High Stakes
**PaperCut** software is extensively deployed across large organizations, including universities, corporations, and government entities, managing a diverse range of printer brands like **Canon**, **Epson**, **Xerox**, and **Brother**. This broad adoption makes the vulnerabilities particularly concerning.
### Immediate Action Recommended
**PaperCut** has urged customers to take immediate steps to secure their installations. This includes removing servers from the public internet and restricting web access to only trusted IP addresses. The company emphasizes that customers must ensure **PaperCut** server web interfaces are unreachable from untrusted internet sources, even if no suspicious activity has been observed.
### Collaborative Effort for a Robust Fix
The initial discovery and reproduction of the vulnerability were aided by a university customer's security team. While an initial patch was released, it was found to be insufficient. **PaperCut** subsequently collaborated with cybersecurity experts from **Huntress** and **watchTwr** to develop a more robust patch, which was released on Friday.
Multiple cybersecurity firms, including **Rapid7** and **Huntress**, have confirmed evidence of exploitation. **Huntress** reported at least two customers impacted by campaigns targeting these vulnerabilities.
### A Persistent Target for Attackers
Jake Knott, Head of Threat Intelligence at **watchTwr**, highlighted why **PaperCut** is a prime target. "**PaperCut** is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated," Knott stated.
Previous **PaperCut** vulnerabilities have been exploited by ransomware gangs and opportunistic attackers for initial access. In 2023, U.S. law enforcement agencies warned that ransomware groups like **Bl00dy** and **Clop** were exploiting **PaperCut** bugs. The **Cybersecurity and Infrastructure Security Agency (CISA)** specifically issued an advisory for K-12 schools, noting the education sector's particular exposure to these vulnerabilities. **Microsoft** also reported that an Iranian state-backed group, known for attacking critical infrastructure, exploited a similar bug in multiple attacks that year.
