Skip to content
Threat Feed
high advisory

Active Exploitation of PaperCut MF and NG

PaperCut MF and NG are impacted by two actively exploited vulnerabilities, CVE-2026-82078 and CVE-2026-81578, which allow unauthenticated remote attackers to achieve arbitrary code execution and full system control.

CVE search metadata

CVE search record: CVE-2026-82078. Severity: critical. CVSS: 9.1. EPSS: 0.93%. KEV: no. Product: PaperCut MF, PaperCut NG, PaperCut Hive, NG/MF. Brief: Active Exploitation of PaperCut MF and NG. Brief link: https://feed.craftedsignal.io/briefs/2026-08-papercut-vulnerabilities/

CVE search record: CVE-2026-81578. Severity: critical. CVSS: 9.8. EPSS: 0.77%. KEV: no. Product: PaperCut MF, PaperCut NG, PaperCut Hive, NG/MF. Brief: Active Exploitation of PaperCut MF and NG. Brief link: https://feed.craftedsignal.io/briefs/2026-08-papercut-vulnerabilities/

What's new

  • 1. added CVE-2026-81578 +1 Sep 5, 07:52 via the-hacker-news
  • 2. new IOCs Sep 2, 18:08 via socprime
  • 3. new product Aug 31, 17:52 via cisa-kev
  • 4. poc_available; OS windows Aug 29, 03:07 via elastic
  • 5. added CVE-2026-81578 +1 Aug 28, 15:10 via anssi

The Netherlands National Cyber Security Centre (NCSC-NL) has issued an urgent alert regarding the active exploitation of two critical vulnerabilities within PaperCut MF and PaperCut NG print management software. Identified as CVE-2026-82078 and CVE-2026-81578, these flaws enable unauthenticated remote attackers to compromise the print management environment. By bypassing authentication mechanisms, adversaries can gain full control over the application, leading to arbitrary code execution. This level of access provides a significant foothold within an organization's network, increasing the risk of lateral movement, data theft, and operational disruption. Given that exploitation is currently observed in the wild, the NCSC strongly advises organizations to verify their version status against the vendor's security bulletin and apply the provided patches immediately.

Impact

Successful exploitation of these vulnerabilities allows attackers to seize control of the PaperCut environment without valid credentials. This results in the potential for complete system compromise, enabling further unauthorized access to sensitive internal systems and data. The risk of lateral movement from the compromised print server to other network segments represents a high-impact threat to organizational security and business continuity.

Recommendation

  • Identify all instances of PaperCut MF and PaperCut NG within the network and verify if they are running vulnerable versions.
  • Apply the vendor-provided security updates for CVE-2026-82078 and CVE-2026-81578 as a matter of urgency.
  • Perform log analysis on the PaperCut server for anomalous activity, such as unexpected process spawning or unauthorized access attempts, as documented in the official PaperCut security bulletin.
  • If the environment status is unknown, contact IT service providers immediately to facilitate an audit and patching effort.

Immediate actions

Patch PaperCut MF and NG instances to remediate CVE-2026-82078 and CVE-2026-81578

IT Operations 24h

Threat Hunt

Anomalous process creation or unexpected network traffic originating from the PaperCut server

T1203 high high confidence hunt now

Data: Process creation logs (Event ID 1), Network connection logs

Mitigations

Apply vendor patches

immediate IT Operations

CVE-2026-82078, CVE-2026-81578

Indicators of compromise

2

ip

TypeValue
ip45.142.193.132
ip194.180.48.134