The printer management software manufacturer PaperCut has issued an emergency notice warning that its PaperCut NG and MF programs are being actively exploited by threat actors.
The company has released patches to fix the vulnerabilities, which have been identified as CVE-2026-82078 and CVE-2026-81578, and rated with a severity higher than 8.8 out of 10.
“The PaperCut Software security response team is investigating the active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed incidents from customers and are treating this matter with the highest priority,” the firm stated.
PaperCut’s software programs are widely used in large organizations, such as universities, corporations, and governments. These use them to manage various brands of printers, such as Canon, Epson, Xerox, Brother, and others.
To prevent further damage, PaperCut has advised its customers to disconnect their servers from the Internet and restrict web access only to trusted IP addresses. The company encourages taking this measure even if no suspicious activity has been observed.
Additionally, the company reportedly used information provided by a university client’s security team to reproduce the vulnerability and develop a solution.
Applying patches
Unfortunately, the patch initially released by PaperCut did not provide a definitive solution to the breaches. As a result, the software manufacturer has been working with experts from Huntress and watchTwr to create a new patch.
Unfortunately, there is evidence that ransomware groups and other opportunistic attackers have taken advantage of PaperCut’s previous vulnerabilities.
“PaperCut is a prime target for attackers of any kind, as it not only serves as a gateway to a corporate environment via the Internet but also is a treasure trove of confidential information if printed documents can be stored and extracted,” highlighted Jake Knott, head of threat intelligence at watchTowr, as reported by The Record Media.
In 2023, U.S. law enforcement had already warned that extortion gangs (such as Cl0p or Bl00dy) were exploiting PaperCut vulnerabilities, particularly in the realm of primary and secondary schools.
Similarly, Microsoft also did the same a few months ago and warned that a state-backed Iranian group, known for attacking critical infrastructures, exploited the same vulnerability.
