PaperCut Flaw Under Active Attack: Critical Bugs Hit Printer Management Software
PaperCut Software has issued an emergency advisory warning customers that two critical vulnerabilities in its widely-used print management software are under active exploitation by cybercriminals. The bugs, tracked as CVE-2026-82078 and CVE-2026-81578, affect PaperCut NG and PaperCut MF and both carry severity scores exceeding 8.8 out of 10. The company's software manages printers from major brands including Canon, Epson, Xerox, and Brother across universities, corporations, and government agencies worldwide.
Multiple cybersecurity firms, including Huntress and watchTowr, have confirmed evidence of exploitation in the wild. Huntress reported at least two customers impacted by the campaign, while PaperCut said it reproduced the vulnerability using information supplied by a university customer's security team. An initial patch failed to fully remediate the flaws, prompting PaperCut to collaborate with Huntress and watchTowr experts on a new fix released Friday. Jake Knott, head of threat intelligence at watchTowr, warned that PaperCut remains a prime target because it serves as both "an internet-facing pivot into a corporate environment" and "a sensitive information treasure trove" for stored and exfiltrated printed documents.
The current campaign echoes a pattern observed in 2023, when ransomware gangs Bl00dy and Clop exploited previous PaperCut bugs to gain initial access to victim networks. The Cybersecurity and Infrastructure Security Agency (CISA) issued a specific advisory for K-12 schools, highlighting the education sector's particular exposure. Microsoft also disclosed that year that an Iranian state-backed group exploited similar PaperCut vulnerabilities in multiple attacks against critical infrastructure targets.
PaperCut urged administrators to immediately remove their servers from public internet access and restrict web interfaces to trusted IP addresses only. Defenders should audit exposed services using our port scanner to identify any inadvertently accessible PaperCut servers, verify proper certificate configurations with our SSL/TLS checker, and run a comprehensive privacy checkup to surface other potential attack surfaces. "Take this action now, even if you have not observed suspicious activity," the company said.