Multiple customers reportedly compromised as security researchers uncover flaws capable of enabling remote code execution.
PaperCut has released emergency security patches after threat actors exploited a chain of vulnerabilities in its print-management software. The attacks have already affected multiple customers, prompting security researchers and government agencies to urge organizations using PaperCut NG and PaperCut MF to act immediately. The attack involves two flaws identified as CVE-2026-81578 and CVE-2026-82078.
The first is an access-control weakness that allows an unauthorized attacker to alter certain PaperCut system configurations. The second involves unsafe dynamic class loading and could allow arbitrary Java bytecode to execute. Individually, the vulnerabilities pose significant security concerns. Combined, however, researchers found they could provide a direct route to compromise a PaperCut application server without a username or password.
Researchers find patch bypass.
The incident has become more serious because researchers found ways around PaperCut’s initial fixes. Huntress researchers reproduced the exploit and identified a bypass affecting the first round of patches.
Security researchers at watchTowr also reported finding bypasses in the original remediation. PaperCut subsequently issued additional fixes. Huntress said the second set of patches withstood its proof-of-concept testing, although organizations are still being advised to treat exposed systems as a potential security risk.
Confirmed customer compromises.
Cybersecurity companies investigating the incidents have reported successful compromises. Rapid7 said it had identified multiple affected customers and observed attackers taking further steps after gaining access.
Researchers reported threat actors deploying remote-management tools to maintain persistence, increase privileges, and potentially move between systems. This means that exploiting the PaperCut vulnerabilities can be only the beginning of a wider intrusion rather than an isolated software compromise. The US Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities catalogue.
Federal civilian agencies have been given separate deadlines to address the two flaws, underscoring the seriousness of the active exploitation. The development also places additional pressure on organizations to assess whether their PaperCut servers have been exposed to the internet. Security researchers are recommending that organizations remove PaperCut application servers from direct public internet exposure and restrict access to trusted networks.



