Vulnerability

Active exploits hit PaperCut NG/MF printers, patches rushed out

⏱️ 4 min read📅 8/29/2026👁️ 15 views

Active exploits confirmed

Microsoft disclosed that an Iranian state‑backed group has already leveraged the same PaperCut flaw in real‑world attacks. PaperCut’s emergency advisory confirms that both CVE‑2026‑82078 and CVE‑2026‑81578 are being exploited in the wild, each scoring above 8.8 on the CVSS scale.

Technical specifics

The two vulnerabilities reside in PaperCut NG and PaperCut MF, the software that controls networked printers and copiers. Exploitation grants an attacker unauthenticated access to the management console, opening a path to execute arbitrary commands on the host server. Huntress reported at least two of its customers hit by the campaign, proving the threat is not theoretical.

PaperCut initially released patches for both CVEs, but a follow‑up patch was needed because the first did not fully close the attack surface. The vendor recommends removing exposed PaperCut servers from the public internet and limiting web access to known, trusted IP ranges.

Who’s at risk

Any organization running PaperCut NG or MF on a publicly reachable server is in the crosshairs. The advisory was drafted with input from a university security team, and past incidents show ransomware gangs like Bl00dy and Clop have abused earlier PaperCut bugs to gain footholds. In 2023, CISA even issued guidance for K‑12 schools using the product.

Immediate mitigations

  • Apply the latest cumulative patch from PaperCut without delay.
  • Confirm the patch resolves both CVE‑2026‑82078 and CVE‑2026‑81578; verify version numbers.
  • Place PaperCut servers behind a firewall and restrict HTTP/HTTPS access to corporate IP ranges or VPN.
  • Audit logs for any unexpected remote console sessions dating back to the advisory release.
  • Consider moving the management interface to an internal network segment if internet exposure is not required.

Those steps buy you time while you review broader printer security hygiene. Remember: a compromised print server can become a launchpad for lateral movement, especially when ransomware groups are watching.

#PaperCut#CVE-2026-82078#CVE-2026-81578#ransomware#printer security#patch