Threat actors have shifted from reconnaissance to active 'hands-on-keyboard' intrusions exploiting CVE-2026-82078 and CVE-2026-81578 in PaperCut NG/MF. CISA has officially added these to its KEV catalog.

  • Two critical vulnerabilities in PaperCut NG/MF are being chained for remote code execution.
  • Attackers are now performing active manual intrusions rather than automated probes.
  • CISA has mandated federal agencies to patch these flaws by September 14.

The cyber threat landscape has shifted dramatically regarding the PaperCut NG/MF print management solutions. What began as a warning about a zero-day vulnerability on August 27 has now evolved into a widespread campaign where threat actors are actively infiltrating corporate networks.

The attack chain involves two specific vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578. These flaws allow unauthenticated attackers to bypass security protocols and execute remote code, effectively giving them full control over the affected instances.

Why This Matters

BozokMedia analysis shows that the sophistication of these attacks is higher than the industry average. According to WatchTowr, attackers are deploying in-memory payloads to ensure exclusive access to compromised hosts. This indicates the presence of 'Initial Access Brokers'—specialists who breach a network and then sell that access to ransomware gangs or state-sponsored actors for higher profits.

"If exposed to the Internet and unpatched, systems should be assumed compromised by an active attacker who is combing through hosts for valuable targets."

The urgency of the situation is underscored by CISA adding these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. With over 1,000 PaperCut instances currently exposed to the public internet, the attack surface is dangerously wide.

Security researchers from Huntress and Rapid7 have provided technical deep-dives into the flaws. They warn that because the attackers are now in the 'hands-on-keyboard' phase, simply applying a patch is an insufficient response. Patching prevents new entries but does not evict an attacker who has already established persistence within the system.

Did You Know?: 'Network Pivoting' is a technique where an attacker uses one compromised system as a jumping-off point to attack other, more secure systems within the same internal network.

Vulnerability Analysis

CVE IDPrimary ImpactRisk Level
CVE-2026-82078Authentication BypassCritical
CVE-2026-81578Remote Code Execution (RCE)Critical

Frequently Asked Questions

Q1: Is patching enough to secure my network?
A: No. If the system was exposed, you must trigger an incident response process to check for existing backdoors or remote access tools.

Q2: Who is most at risk?
A: Any organization using PaperCut NG/MF that has the management interface exposed to the public internet without a VPN or strict firewall rules.