PaperCut exploitation escalates to active intrusions

PaperCut exploitation escalates to active intrusions

Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have increased, with threat actors shifting from reconnaissance activities to hands-on keyboard activities.

PaperCut first warned users of its NG and MF print management solutions on August 27 about an actively exploited zero-day vulnerability. It later emerged that threat actors had chained two vulnerabilities in their attacks.

The vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578 and can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.

The vendor quickly deployed two emergency patches – one after bypassing the first – and is working on an official release that addresses both vulnerabilities.

The attacks are now escalating, according to exposure management company WatchTowr, whose researchers have been monitoring the situation.

“The activity has evolved significantly, and quickly – we are no longer seeing purely exploratory investigations to identify vulnerable systems, but rather real-world exploitation accompanied by hands-on keyboard interaction of human attackers exploring systems they have compromised,” Jake Knott, head of threat intelligence at WatchTowr, said by email.

Advertising. Scroll to continue reading.

“In the context of this activity, it is notable that this appears to be ‘above average’ in terms of sophistication (the bar is still very low) – some of which are simply designed to facilitate moving from external to internal networks and perpetuate attacks,” Knott added. “Attackers are, as always, selfish – they encrypt access to their deployed in-memory payloads to ensure that only they can access compromised hosts and proceed. This behavior is mirrored by first access brokers and other more aggressive operators.”

PaperCut’s updated compromise indicators (IoCs) also indicate an escalation of the attack, particularly the use of remote access tools on target systems.

Technical details about CVE-2026-82078 and CVE-2026-81578 are also available from security companies huntress And Rapid7.

The Cybersecurity Authority CISA added CVE-2026-82078 and CVE-2026-81578 were added to the Known Exploited Vulnerabilities (KEV) catalog on Monday. Federal authorities were ordered to correct the deficiencies by September 14th.

More than 1,000 PaperCut NG/MF instances exist exposed to the internetaccording to ShadowServer.

“If systems have been exposed to the Internet in the last few days and have not been patched, it should be assumed that they have been compromised by an active attacker scouring vulnerable hosts in search of interesting or valuable targets,” WatchTowr’s Knott warned. “And if you haven’t already, now is the time to trigger incident response processes. Patching alone locks out new attackers while allowing existing attackers to maintain access and move forward.”

Related: Nightmare Eclipse drops Kaspersky product exploit “HardBreacher”.

Related: ServiceNow addresses three critical code injection vulnerabilities

Related: Critical Ruby on Rails vulnerability in attackers’ crosshairs

Leave a Reply

Your email address will not be published. Required fields are marked *