PaperCut warns of hackers using printer management software flaw in attacks

The company behind a popular brand of printer management software warned customers of a new vulnerability currently being used by cybercriminals.
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation. The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the company said.
PaperCut’s software is used widely across large organizations like universities, corporations and governments. Organizations use PaperCut software to manage a variety of printer brands including Canon, Epson, Xerox, Brother and more.
The company urged customers to remove their servers from the public internet and restrict web access to only trusted IP addresses. Customers need to take every step to ensure PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.
“Take this action now, even if you have not observed suspicious activity,” PaperCut said.
In the security advisory issued on Thursday, the company said it used information provided by a university customer’s security team to reproduce the vulnerability and develop a fix.
Multiple cybersecurity companies confirmed evidence of exploitation including Huntress, which said it has at least two customers impacted by the campaign targeting the bugs.
An initial patch issued by PaperCut did not sufficiently address the vulnerabilities and the company said it worked with experts from Huntress and watchTwr to create a new patch released on Friday.
Jake Knott, head of threat intelligence at watchTowr, noted that previous PaperCut vulnerabilities were used by ransomware gangs and opportunistic attackers to gain initial access.
“PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated,” Knott said.
In 2023, U.S. law enforcement agencies warned that ransomware gangs like Bl00dy and Clop were exploiting PaperCut bugs. The Cybersecurity and Infrastructure Security Agency (CISA) specifically issued an advisory for K-12 schools that said the education sector is particularly exposed to PaperCut vulnerabilities.
Microsoft said an Iranian state-backed group known for attacking critical infrastructure exploited the same bug that year in multiple attacks.
References in this story
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) www.papercut.com Short description of what is in the security bulletin
- Rapid7 www.rapid7.com On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer…
- PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE | Huntress www.huntress.com PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching and exposure guidance.
- CISA: Bl00dy Ransomware Gang using printer vulnerability to attack schools therecord.media The Cybersecurity and Infrastructure Security Agency (CISA) and FBI said a relatively new ransomware group has been exploiting an issue with a popular printing software to attack schools across the U.S.
- CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalog therecord.media The Cybersecurity and Infrastructure Security Agency (CISA) added an issue affecting a popular print management software tool to its list of exploited vulnerabilities on Friday.
- Iranian state-sponsored hackers exploiting printer vulnerability therecord.media Hackers based in Iran are exploiting a recently-discovered vulnerability affecting a popular printing management software, according to new research.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



