Vulnerabilities

PaperCut Attacks Escalate to Hands-On Intrusions as CISA Sets Deadline

Attackers exploiting two PaperCut NG/MF vulnerabilities have stopped scanning and started working inside the systems they have already compromised. WatchTowr, which has tracked exploitation since the first advisory, reports human operators exploring compromised hosts rather than automated probes hunting for vulnerable instances. CISA added both flaws to its Known Exploited Vulnerabilities catalogue on 31 August and gave US federal agencies until 14 September to fix them.

If a PaperCut Application Server has been internet-facing and unpatched at any point over the past week, patching it now does not close the incident. Jake Knott, head of threat intelligence at WatchTowr, told SecurityWeek that such systems should be assumed compromised and that patching locks out new attackers while leaving the ones already inside untouched. That is an incident response trigger not a maintenance ticket.

Two Emergency Patches in One Day, and the First Was Bypassed

PaperCut Software published an urgent security bulletin on 27 August. Rapid7 records the first emergency patch arriving the next day for PaperCut NG/MF versions 25 and 26 with version 24 covered later the same day by a second patch that added further hardening. WatchTowr had found multiple bypasses of the first fix plus an additional authentication bypass. Five days after disclosure, the official release that addresses both CVEs is still being built.

The attack is a chain of two flaws. CVE-2026-81578 rated 8.8, is an authentication bypass in the PaperCut NG/MF web management interface, unauthenticated remote requests aimed at administrative functions can trigger backend actions before access validation finishes. CVE-2026-82078 rated 9.4, is unsafe dynamic class loading in the database connection utilities, where the application loads driver classes by configurable name without checking them against an allowlist. PaperCut’s advisory describes the result as “the execution of arbitrary Java bytecode residing on the application classpath” under the server process. Chained, the two give pre-authentication remote code execution. Rapid7 reports that a Metasploit module now exists to validate exposure.

The Two Monitoring Firms Are Describing Different Attacks

Huntress saw attacks against at least two of its customers with the earliest exploitation attempts on 26 August. Its analysts described the observed activity as system discovery and reported no secondary malware, no command-and-control traffic and no persistence recovered from the payload they pulled apart.

WatchTowr describes something further along. Knott points to in-memory payloads keyed so that only the original attacker can reach the compromised host and tooling built to pivot from the external network to the internal one, behaviour he reads as consistent with initial access brokers.

The capability assessment comes from the firm that has been publishing its own analysis of these flaws all week and Knott himself notes the bar is low. The duller evidence is the stronger evidence, PaperCut has updated its published indicators of compromise to cover remote access tools being deployed on targeted systems and CISA does not add CVEs to KEV on the strength of a vendor blog post. Nobody has attributed the campaign to anyone. Given that the 2023 PaperCut exploitation was eventually tied to Clop, LockBit, the Bl00dy gang and an Iranian state-backed group, that restraint is worth something.

Roughly 1,000 Servers Are Reachable From the Internet

The ShadowServer Foundation counts more than 1,000 PaperCut NG/MF instances exposed to the internet, a majority of them in North America and Europe. Print management rarely gets attention in an asset inventory which is part of what makes it useful to an intruder. The PaperCut Application Server is a Java application with privileged access to print infrastructure wired into Active Directory, Entra ID or LDAP for user synchronisation and it usually sits well inside the network.

Nordic Universities Sit in the Middle of This

The first confirmed victim to report the exploitation was a university whose security and forensics teams supplied the information that let PaperCut reproduce the flaw, according to Rapid7. Nordic higher education runs the same software. Lund University documents PaperCut as the system behind campus-wide pull-printing for students, employees and library visitors, tied to LUCAT identity accounts. There is no indication that Lund has been affected and its own IT pages are the source here. It is a fair picture of the deployment now in scope, one Java application server joined to the identity directory, serving tens of thousands of accounts.

Check Whether You Were Already Hit, Then Patch

  1. Apply the second emergency patch to every PaperCut NG/MF Application Server running version 24, 25 or 26 including servers that already took the first one.
  2. Take the Application Server off the public internet. PaperCut’s guidance is to restrict access to trusted IP addresses whether you have patched or not.
  3. Run PaperCut’s updated indicators of compromise before and after patching and look specifically for remote access tools nobody installed deliberately.
  4. If the server was internet-facing and unpatched at any point since 26 August, open an incident, review the directory accounts it synchronises with and treat it as a foothold rather than a print server.

The official release that fixes both CVEs does not exist yet. The emergency patches do.

Reference

  1. PaperCut Exploitation Escalates to Active Intrusions
  2. More Details Emerge on Exploited PaperCut Vulnerabilities
  3. URGENT Security Advisory: PaperCut NG/MF Security Bulletin, 27 Aug 2026
  4. CISA Adds Two Known Exploited Vulnerabilities to Catalog
  5. PaperCut NG/MF Critical Zero-Day Exploited in the Wild
  6. PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
  7. PaperCut Releases Second Emergency Patch for Exploited Flaws
  8. PaperCut Warns of Hackers Using Printer Management Software Flaw in Attacks

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.