Two vulnerabilities (CVE-2026-82078, CVE-2026-81578) affecting print management solutions PaperCut NG and PaperCut MF are being exploited by attackers, PaperCut Software has warned.
“We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said.
What is PaperCut NG/MF?
PaperCut NG is print management software for places like offices, schools, and other organizations.
PaperCut MF (“Multi-Function”) is the upgraded version that works directly with the big all-in-one office copier machines that print, copy, scan, and fax. The software is embedded in and accessible from the machine’s touchscreen, and works with copiers from most major brands.
NG watches and manages the printing from the computer and server side, while MF does all of that, and connects to the copier machines for extra security and features.
“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses),” the company urged.
The Application Server is the “brain” of both PaperCut NG and MF, and there’s normally just one per organization.
Restrict access, look for signs of compromise
The vendor said they would publish specific indicators of compromise when they pinpoint them.
In the meantime, users should be on the lookout for general indicators of compromise, such as:
- Alerts from intrusion detection, endpoint security, or network monitoring tools involving the PaperCut Application Server (particularly suspicious post-exploitation activity from pc-app.exe)
- Missing, unexpectedly truncated, or deleted PaperCut server.log files
- The presence of either ERROR No suitable driver found for jdbc:no:x or ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST in server.log.
But even if they don’t find any, users should restrict access to the Application Server.
“Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses,” the vendor advised.
In 2023, affiliates of the Clop and LockBit ransomware-as-a-service outfits leveraged two known vulnerabilities – CVE-2023-27350 and CVE-2023-27351 for remote code execution and information disclosure – in the same software.
UPDATE (August 27, 2026, 13:20 a.m. ET):
PaperCut Software has released emergency patches for PaperCut NG and MF versions 25 and 25.
“PaperCut’s security emergency response team has used information provided by a university customer’s security team and digital forensics and incident response team. This information has enabled PaperCut to reproduce a vulnerability in the PaperCut NG and PaperCut MF code,” the company said in an update of the intial advisory.
UPDATE (August 28, 2026, 09:25 a.m. ET):
PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch.
CVE-2026-82078 stems from unsafe dynamic class loading in the database connection utilities of PaperCut MF and PaperCut NG, and CVE-2026-81578 is an improper access control vulnerability in the web management interface of the two solutions.
The latter allows unauthenticated remote attackers to modify certain system configurations, and the former to execute arbitrary Java bytecode.
“Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch,” the vendor advised.
“Huntress has seen limited exploitation on two customer environments; post-exploitation activity included base64-encoded commands executed on the targeted server that decoded to commands (whoami & ver) that aimed to identify the victim’s user account and operating system,” Huntress researchers John Hammond and Andrew Brandt shared.
“Huntress also reproduced a pre-authentication, remote configuration takeover and a complete remote code execution chain against a stock installation of PaperCut NG 25.0.11.75758, the previous public version listed in PaperCut’s 25.0 release history.”
The headline and lead of this article have been changed to reflect the newest findings regarding these active attacks.