PaperCut Zero-Days Have Moved Past Scanning — Attackers Are Now Stealing Data
- The Mess: Two PaperCut zero-days are no longer just being used to probe vulnerable servers. Attackers are chaining an authentication bypass with a critical code-execution flaw, then moving inside compromised systems and stealing data.
- The Damage: A public-facing PaperCut server can become an unauthenticated entry point into an organization, giving attackers access to server data and a potential path toward the internal network.
- The Fix: Install PaperCut Emergency Patch Release 3 immediately, remove exposed Application Servers from the public internet and investigate every system that was reachable before patching.
The PaperCut situation escalated fast.
First, attackers were exploiting a zero-day.
Then researchers identified a second vulnerability and showed that the two could be chained.
Now the attacks have moved beyond reconnaissance.
Threat intelligence researchers are observing attackers using the PaperCut flaws during real intrusions, including hands-on-keyboard activity, remote-access tooling and data theft.
This is no longer a vulnerability story.
It is an active intrusion story.
Two Bugs. One Dangerous Chain.
The attack chain involves:
CVE-2026-81578 — an authentication bypass vulnerability affecting the PaperCut web management interface.
CVE-2026-82078 — a critical unsafe dynamic class-loading vulnerability that can execute arbitrary Java bytecode in the context of the PaperCut server process.
Individually, both bugs are serious.
Together, they are much worse.
The authentication bypass allows an unauthenticated attacker to reach privileged functionality and manipulate configuration.
The second flaw can then be used to execute code.
No stolen password.
No administrator account.
No user interaction.
The vulnerable PaperCut server can become the entry point.
The Attackers Are No Longer Just Looking
Early activity focused on identifying vulnerable systems.
That phase did not last long.
Security researchers now report attackers performing interactive post-compromise activity on systems reached through the PaperCut vulnerabilities.
This includes activity designed to help attackers explore compromised environments and pivot from externally exposed PaperCut infrastructure toward internal systems.
That is a major escalation.
Scanning tells an attacker what is vulnerable.
Hands-on-keyboard activity means somebody decided the compromised system was worth investigating.
And once a human attacker starts exploring an enterprise environment, patching alone becomes insufficient.
The attacker may already be inside.
Data Theft Is Already Happening
Researchers monitoring the attacks have also observed a separate exploitation path focused directly on data theft.
Instead of immediately using the vulnerabilities for the most obvious remote code execution path, attackers have reportedly abused the authentication bypass to manipulate PaperCut’s external user lookup.
From there, they targeted database data.
In observed activity, attackers dumped database tables using the embedded Apache Derby database.
That means the PaperCut server itself can contain information valuable enough to steal.
The attack does not need to turn into ransomware to be damaging.
Data theft is already an outcome.
More Than a Printer Server
This is the part organizations often underestimate.
PaperCut sounds like printing infrastructure.
Printing infrastructure sounds boring.
Boring infrastructure often gets patched slowly.
But PaperCut sits inside enterprise environments.
It can integrate with:
- Active Directory
- identity systems
- databases
- user directories
- print servers
- network storage
- external authentication services
The server may have credentials.
It may know about users.
It may connect to internal infrastructure.
An attacker does not necessarily compromise PaperCut because they care about printers.
They compromise it because it is already inside the network.
CISA Added Both Bugs to KEV
The seriousness of the attacks is reflected in the U.S. government’s response.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog.
That means the exploitation is not being treated as theoretical.
Federal agencies now have a deadline to address the flaws.
For everyone else, the message should be obvious.
If the system was internet-facing, patching should already be happening.
And if the system was exposed before patching, it should be investigated.
Patch Release 3 Is the Current Fix
PaperCut’s emergency response evolved quickly.
The first emergency patch was followed by another release after researchers identified additional bypass possibilities.
The company then released Emergency Patch Release 3, which supersedes the earlier emergency releases and includes additional hardening.
That detail matters.
Installing an earlier emergency patch does not necessarily mean you are finished.
PaperCut recommends installing Release 3 even if one of the previous emergency patches was already applied.
This is one of those incidents where patch version history matters.
More Than 1,000 Servers Are Exposed
Internet scanning data has identified more than a thousand PaperCut NG and MF instances exposed online.
The exact number of vulnerable systems is harder to determine because exposure does not automatically mean an instance remains unpatched.
But exposed infrastructure creates an obvious hunting ground.
Attackers do not need a victim list.
They can scan.
Find PaperCut.
Test the attack path.
Move on to the next server.
The more systems remain publicly reachable, the easier that process becomes.
Patching Is Not Proof of Safety
This is probably the most important operational point.
If your PaperCut server was exposed to the internet before the latest emergency patch was installed, you should not assume:
“We patched it, so we’re safe.”
The patch stops new exploitation.
It does not remove:
- attacker persistence
- stolen credentials
- deployed remote-access tools
- malicious processes
- modified configuration
- data already copied from the server
Organizations should review PaperCut’s indicators of compromise and investigation guidance.
Look for activity that occurred during the exposure window.
What Administrators Should Do Now
If you run PaperCut NG or MF:
- Identify every Application Server and Site Server.
- Check whether any instance is accessible from the public internet.
- Install Emergency Patch Release 3 immediately.
- Remove unnecessary public exposure.
- Review PaperCut indicators of compromise.
- Check for suspicious database activity.
- Investigate unexpected remote-access tools or processes.
- Review credentials and integrations reachable from the PaperCut server.
The last point matters.
If attackers reached the PaperCut host, the question is no longer limited to PaperCut.
The question becomes what the server could reach next.
The 2023 PaperCut Lesson Is Back
PaperCut has been here before.
In 2023, other vulnerabilities in the platform were exploited by ransomware operators and state-backed groups.
Attackers learned that print-management infrastructure can provide useful access to enterprise networks.
The 2026 campaign proves the lesson was not forgotten.
A product does not stop being interesting to attackers simply because the previous vulnerabilities were patched.
New bugs appear.
Old infrastructure remains exposed.
The cycle starts again.
Bugstoday Opinion
The escalation here is the real story.
A zero-day becoming an exploit is bad.
A public exploit becoming mass scanning is worse.
But attackers moving from scanning into hands-on-keyboard activity and data theft means the compromise window is already open.
PaperCut administrators should stop thinking about this as another item in the patch queue.
Bugstoday verdict: If your PaperCut server was exposed before you installed Emergency Patch Release 3, patching is only step one. Assume the attacker may have already had time to look around — because in some environments, they already did.
Today’s Bugs. Tomorrow’s Breaches.
Sources
- PaperCut — Security Bulletin, 27 August 2026
- CISA — Known Exploited Vulnerabilities Catalog
- Huntress — PaperCut NG/MF Active Exploitation Research
- Shadowserver Foundation
- PaperCut — Emergency Patch Release 3




