PaperCut patches two critical flaws under
PaperCut warns of active exploitation of two high-severity vulnerabilities (CVE-2026-82078 and CVE-2026-81578) in its print management software, urging

PaperCut Software has issued an emergency advisory warning that two critical vulnerabilities in its print management software are under active exploitation by cybercriminals. The company released patches for the flaws, tracked as CVE-2026-82078 and CVE-2026-81578, both of which carry severity scores over 8.8 out of 10.
In a statement released on Thursday evening, the company's security response team said it is investigating active exploitation affecting PaperCut NG and PaperCut MF. "We are aware of confirmed customer incidents and are treating this matter with the highest priority," the company stated. The advisory was based on information provided by a university customer's security team, which helped PaperCut reproduce the vulnerability and develop a fix.
Vendor-issued patches for CVE
The company's initial patch did not fully address the vulnerabilities. PaperCut said it subsequently worked with experts from cybersecurity firms Huntress and watchTowr to create a new patch, which was released on Friday. Multiple cybersecurity companies, including Huntress, have confirmed evidence of exploitation, with Huntress reporting at least two impacted customers.
| CVE Identifier | Severity Score (CVSS) | Affected Software |
|---|---|---|
| CVE-2026-82078 | > 8.8 | PaperCut NG, PaperCut MF |
| CVE-2026-81578 | > 8.8 | PaperCut NG, PaperCut MF |
Unified security posture management
PaperCut urged all customers to take immediate action to secure their systems. The company's primary recommendation is to remove PaperCut servers from the public internet entirely. Customers must restrict web access to only trusted IP addresses. "Take this action now, even if you have not observed suspicious activity," the advisory stressed. The goal is to ensure the software's web interfaces cannot be reached from untrusted internet addresses.
PaperCut software is widely deployed across large organizations, including universities, corporations, and governments. It is used to manage printers from brands like Canon, Epson, Xerox, and Brother.
A history of targeted exploitation
Jake Knott, head of threat intelligence at watchTowr, explained why the software is a frequent target. "PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated," Knott noted. He added that previous PaperCut vulnerabilities have been used by ransomware gangs and opportunistic attackers to gain initial access.
This pattern of exploitation is well-documented. In 2023, U.S. law enforcement agencies warned that ransomware gangs like Bl00dy and Clop were actively exploiting PaperCut bugs. The Cybersecurity and Infrastructure Security Agency (CISA) issued a specific advisory for K-12 schools, noting that the education sector is particularly exposed to these vulnerabilities. That same year, Microsoft reported that an Iranian state-backed group known for attacking critical infrastructure had exploited a PaperCut vulnerability in multiple attacks.





