news.mlab.sh
Back to the feed
vulnerability

PaperCut Exploitation Escalates to Active Intrusions

CriticalCVSS 9.4
Summary

A rapidly escalating exploitation campaign targeting PaperCut NG/MF print management solutions is underway, with threat actors moving beyond reconnaissance to actively compromising systems. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, are being used to gain remote code execution, and over 1,000 instances are currently exposed online. Federal agencies are under pressure to address the flaws by September 14th.

A rapidly escalating exploitation campaign targeting PaperCut NG/MF print management solutions is underway, with threat actors moving beyond reconnaissance to actively compromising systems. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, are being used to gain remote code execution, and over 1,000 instances are currently exposed online. The cybersecurity agency CISA added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Monday, instructing federal agencies to address the flaws by September 14th.

PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August 27. It later emerged that threat actors have been chaining two flaws in their attacks.

WatchTowr’s researchers have observed a significant shift in attack behavior, moving from simple reconnaissance to active exploitation. “Activity has significantly evolved, and it did so quickly — we are no longer seeing purely exploratory probes to identify vulnerable systems, but real-world exploitation accompanied with hands-on-keyboard interaction from human attackers exploring systems they’ve compromised,” Jake Knott, head of threat intelligence at WatchTowr, said via email.

“As part of this activity, it’s noteworthy that this appears to be ‘above average’ (the bar still being very low) in terms of sophistication — some designed purely to facilitate external to internal network pivoting and continue attacks,” Knott added. “Attackers are, as always, being selfish — keying access to their deployed in-memory payloads to ensure that only they are able to access compromised hosts and continue further.”

PaperCut’s updated indicators of compromise (IoCs) also indicate attack escalation, specifically the deployment of remote access tools on targeted systems.

More than 1,000 PaperCut NG/MF instances are exposed to the internet, according to data from ShadowServer. “If exposed to the Internet and unpatched at any stage in the last few days, systems should be assumed compromised by an active attacker who is combing through vulnerable hosts looking for interesting or valuable targets,” WatchTowr’s Knott warned. “And if you haven’t already, now is the time to trigger incident response processes. Patching alone will lock out new attackers while allowing existing attackers to maintain access and go further.”

Related: Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

Related: ServiceNow Patches 3 Critical Code Injection Vulnerabilities

Read the full article at SecurityWeek