PaperCut issued emergency patches on Friday to address critical vulnerabilities in its print-management software.
The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers at Huntress and watchTowr to respond to the attacks.
The vulnerabilities include an improper access-control flaw in PaperCut MF and PaperCut NG. Tracked as CVE-2026-81578, this flaw enables an unauthenticated attacker to modify certain system configurations. An unsafe dynamic class loading flaw, tracked as CVE-2026-82078, enables an attacker to execute arbitrary Java bytecode.
“The exploit technique is chaining these two flaws together for a “point and shoot” full compromise,” John Hammond, senior principal security researcher at Huntress, told Cybersecurity Dive.
Hammond said two confirmed exploitation cases last week involved early-stage reconnaissance. He warned that exploitation could quickly escalate, as no username or password is required, and an attacker needs only a target IP address or hostname to fully compromise the server.
Huntress was able to reproduce a proof-of-concept exploit and uncovered a bypass route against the first set of patches issued by PaperCut. Hammond confirmed that the second set of patches are holding up against the Huntress proof of concept.
Huntress is urging any users to remove the application server from the public-facing internet and limit any access to trusted networks.
Researchers at watchTowr were also able to reproduce the vulnerabilities and discovered bypasses of the initial patches, according to a LinkedIn post.
Cybersecurity firm Rapid7 also confirmed it has multiple customers that have been compromised. Researchers have seen hackers take additional actions once they gain access to a compromised host.
“We have observed threat actors bringing their own remote-management tools to maintain persistence, elevate privileges, and attempt to laterally move,” Seth Lazarus, senior manager, detection and response services at Rapid7, told Cybersecurity Dive.
PaperCut previously came under serious attack in 2023. At the time, the FBI and Cybersecurity and Infrastructure Security Agency warned about multiple threat actors targeting a critical vulnerability in the software.
CISA on Friday added CVE-2026-81578 to its Known Exploited Vulnerabilities catalog, further adding CVE-2026-82078 on Monday. The agency gave a Sept. 11 deadline for Federal Civilian Branch Agencies to remediate for the first flaw and Sept. 14 for the second.
If a customer believes their server has been compromised, PaperCut recommends securing existing server backups, wiping and rebuilding the application server and restoring a clean backup.
