PaperCut Attacks Now Active Intrusions
Threat actors are now conducting hands-on-keyboard intrusions by chaining two critical PaperCut vulnerabilities, CVE-2026-82078 and CVE-2026-81578.

PaperCut attacks exploiting two critical vulnerabilities have escalated. They are now active, hands-on-keyboard intrusions. The exposure management firm WatchTowr reports that human attackers are exploring compromised systems.
These attacks chain two flaws tracked as CVE-2026-82078 and CVE-2026-81578. Unauthenticated attackers can exploit them to bypass authentication. They can then execute remote code on affected PaperCut NG and MF print management servers.
Vendor-Issued Patches for CVE
PaperCut first warned of an actively exploited zero-day on August 27. The vendor has since released two emergency patches. The first patch was bypassed. This prompted a second. PaperCut is now developing an official release to address both vulnerabilities comprehensively.
Jake Knott, head of threat intelligence at WatchTowr, described the shift in attacker behavior. He said activity has significantly evolved, and it did so quickly. We are no longer seeing purely exploratory probes, Knott explained. Instead, there is real-world exploitation accompanied with hands-on-keyboard interaction.
Critical Vulnerability Exploited
The campaign's sophistication is notable. WatchTowr's analysis suggests some attack payloads are designed for network pivoting. They move from external to internal systems to continue operations. Attackers are also keying their in-memory payloads to lock out other threat groups. This is a tactic associated with initial access brokers.
PaperCut's updated indicators of compromise confirm this escalation. They show the deployment of remote access tools on victim systems. More than 1,000 PaperCut NG/MF instances remain exposed to the internet. This is according to data from ShadowServer.
Vulnerability Management and Response
Knott issued a stark warning for organizations. If exposed to the Internet and unpatched at any stage in the last few days, systems should be assumed compromised. He emphasized that patching alone is insufficient. It only locks out new attackers while allowing existing ones to maintain access. Incident response processes must be triggered. For comprehensive vulnerability management, organizations should consult their internal stats and injuries dashboards. This helps assess exposure and impact.
The urgency is underscored by official action. CISA added both CVEs to its Known Exploited Vulnerabilities catalog. Federal agencies have been instructed to apply patches by September 14. Security teams can track the broader threat landscape through our fixtures page. This includes similar critical vulnerabilities.
Technical details on the vulnerabilities are available from security firms Huntress and Rapid7. The escalating attacks highlight the rapid weaponization of critical flaws in widely used software.





