Critical security flaws in PaperCut NG and MF print management software are being actively abused by hackers to steal sensitive data from thousands of organizations globally.

  • Two critical vulnerabilities (CVE-2026-81578 and CVE-2026-82078) are being chained to bypass authentication.
  • Attackers are specifically targeting database tables via Derby to dump sensitive organizational data.
  • Over 800 exposed servers have been identified by Shadowserver, posing a massive risk to 70,000+ organizations.

The cybersecurity landscape has been rocked by the discovery and subsequent exploitation of two zero-day vulnerabilities in PaperCut NG and MF, a widely used print management software. With a massive footprint of 100 million users across more than 70,000 organizations—including government agencies, educational institutions, and Fortune 500 companies—the scale of potential exposure is staggering.

The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, allow sophisticated threat actors to chain an authentication bypass with remote code execution (RCE). While PaperCut Software released emergency patches last Thursday and Friday, the window of opportunity for attackers was already open. Threat intelligence firm Defused has confirmed that these flaws are being actively abused in the wild, specifically to hijack external user-lookups and exfiltrate database content.

Why This Matters

BozokMedia analysis shows that the shift from simple RCE (Remote Code Execution) to targeted data dumping via Derby databases indicates a highly strategic approach by attackers. Rather than just crashing systems or installing ransomware, the current wave of attacks focuses on silent data theft, which can lead to long-term corporate espionage or massive regulatory fines under GDPR and other privacy laws.

The chaining of authentication bypasses with database access represents a critical failure in the trust boundary of print management systems, turning a utility tool into a gateway for corporate espionage.

The risk is further amplified by the fact that Shadowserver has identified over 800 PaperCut servers currently exposed to the public internet. This visibility provides a roadmap for attackers to scan and compromise unpatched systems rapidly.

Historical Background

PaperCut has been a recurring target for high-profile hacking groups. In April 2023, vulnerabilities CVE-2023-27350 and CVE-2023-27351 were exploited by the notorious LockBit and Clop ransomware gangs. Shortly after, Microsoft revealed that Iranian state-backed groups Muddywater and APT35 had also joined the fray, targeting the 'Print Archiving' feature to steal sensitive documents. This pattern suggests that print servers are often overlooked in security audits, making them an ideal entry point for both state-sponsored actors and cybercriminals.

Attack WavePrimary ActorsKey VulnerabilitiesPrimary Goal
2023 AttacksLockBit, Clop, APT35CVE-2023-27350Ransomware & Espionage
2026 AttacksUnknown / Defused ObservedCVE-2026-81578/82078Database Data Theft
Did You Know?: Print servers are often considered 'low-risk' assets, but because they handle every document sent to a printer, they are essentially goldmines for sensitive corporate intelligence.

Frequently Asked Questions

Q1: How can organizations protect themselves from these PaperCut attacks?
Organizations must immediately apply the emergency patches released by PaperCut and ensure their print servers are not exposed to the public internet.

Q2: What specific data are the attackers stealing?
Reports indicate attackers are dumping database tables via Derby, which likely contain user credentials, configuration data, and potentially metadata about printed documents.