security

PaperCut NG/MF Zero-Days Exploited: What Offices Should Check Now

Valley Printer Pros Team
· Updated
7 min read

On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.

Key takeaways

  • PaperCut disclosed on August 27, 2026 that attackers were actively exploiting its NG and MF print-management software, and CISA added the two chained flaws, CVE-2026-81578 and CVE-2026-82078, to its Known Exploited Vulnerabilities catalog on August 31.
  • Chained together, the flaws let an attacker run code on a PaperCut server without a username or password, knowing only the server's IP address or hostname.
  • PaperCut says there are no patches for version 23 or earlier, so offices on those versions must upgrade to version 24, 25 or 26.
  • PaperCut's first instruction for internet-reachable servers is to restrict web access to trusted IP addresses immediately, even with no sign of trouble.
  • California's SB 446 requires notifying affected Californians within 30 calendar days of discovering a breach of their personal information, so talk to counsel early if a compromise exposed such data.
Share:
#papercut#zero-day#print server security#cisa kev#patch management

If your office copier makes people tap a badge before a print job comes out, or someone gets a monthly report of who printed what, there may be a print-management server running quietly in a closet or a virtual machine. If that server runs PaperCut NG or PaperCut MF, it just moved from "someday" to "this week" on your to-do list.

On August 27, PaperCut warned that attackers were actively exploiting its software. Emergency patches followed on August 28, and on Monday, August 31, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both flaws to its catalog of known exploited vulnerabilities. Here's what happened, why it's really a network problem, and what to ask your copier dealer.

What happened with PaperCut last week?

Attackers found a way into PaperCut NG and MF servers before a fix existed, and PaperCut spent the rest of the week shipping emergency patches. In its urgent security advisory, PaperCut said it was investigating active exploitation affecting both products and had confirmed customer incidents, and it treated every NG and MF version as potentially affected. Help Net Security and The Register reported the warning as it unfolded.

The fixes didn't go smoothly. PaperCut released its first emergency patch on August 28 for versions 25 and 26. Researchers at watchTowr Labs found a way around it the same day, and a second emergency patch followed later on August 28 with extra hardening and coverage for version 24, according to SecurityWeek and watchTowr.

DateWhat happened
Thursday, Aug. 27PaperCut issues an urgent advisory: active exploitation of NG and MF, confirmed customer incidents, all versions treated as potentially affected
Friday, Aug. 28First emergency patch for versions 25 and 26; watchTowr Labs finds a bypass; a second emergency patch adds hardening and version 24
Monday, Aug. 31CISA adds both flaws to its Known Exploited Vulnerabilities catalog; PaperCut's updated indicators show remote-access tools on compromised servers

What are CVE-2026-81578 and CVE-2026-82078?

They're two separate flaws that attackers chain together to take over a PaperCut server without logging in.

  • CVE-2026-81578 is an authentication bypass in PaperCut's web management interface. It lets an unauthenticated remote attacker change certain system settings. Arctic Wolf lists it as high severity, with a CVSS score of 8.8.
  • CVE-2026-82078 is a critical flaw, scored 9.4, in PaperCut's database connection utilities. According to PaperCut's advisory, the software loads database driver classes by name without checking them against an allowlist, which lets an attacker run Java code as the PaperCut server process.

Chained, the two give an attacker remote code execution with no username or password, only the server's IP address or hostname, as Cybersecurity Dive and CISA describe.

In plain English: the first bug lets a stranger change a setting they should never be able to touch, and the second turns that setting into a way to run their own code.

Why does a hacked print server matter?

Because it isn't really a printer problem. A print-management server is an ordinary server inside your network, often connected to your user accounts and copiers. Once attackers control it, they're inside instead of knocking on the door.

By August 31 that was no longer theoretical. PaperCut's updated indicators of compromise show attackers setting up a Windows service called "Remote Access Service" that runs SimpleHelp's SimpleService.exe, then downloading AnyDesk, according to PaperCut's advisory and Help Net Security. Help Net Security described the pair as redundant access: remove one, and the other still works.

It's the pattern from our look at remote-access malware using printers as an entry point: the device nobody watches becomes the door nobody locks. Our printer security checklist covers the basics.

Which offices might run PaperCut without realizing it?

Any office where a copier dealer or IT provider set up print release, print-cost tracking or scan workflows, possibly without the owner ever hearing the software's name. Typical candidates:

  • Law firms that bill printing back to client matters (see our law firm printer guide).
  • Medical and dental offices that hold patient paperwork until the right person badges in (see our medical office printer guide).
  • Accounting and tax practices that track print volume by client.
  • Schools and training centers with student print quotas.

A system that was installed years ago and never revisited is exactly the one to worry about, because of the next point.

Is there a patch for my PaperCut version?

If you're on version 24, 25 or 26, yes. If you're on version 23 or earlier, no. PaperCut's advisory says there are no emergency patches or maintenance releases for version 23 or earlier, and those customers need to upgrade to a supported line (24, 25 or 26). Huntress and the Canadian Centre for Cyber Security report the same limitation.

For supported versions, the fix as of August 31 is the second emergency patch, Emergency Patch Release 2, which covers all three version lines, according to BleepingComputer and the Canadian Centre for Cyber Security.

CISA gave federal civilian agencies until September 14 to deal with both flaws, according to CISA's catalog entry and The Hacker News. Your business isn't bound by that deadline, but it's a fair yardstick: two weeks, not two quarters.

What this means for San Fernando Valley offices

For Valley law firms, medical and dental practices, accounting offices and schools, the risk is a print server nobody remembers, reachable from the internet, on a version nobody has updated. It doesn't matter whether you're in Woodland Hills or Burbank: attackers who need only an IP address don't care about ZIP codes, so the same checks apply across all the communities we serve.

There's also a California-specific reason not to wait. SB 446, enacted in October 2025, changed the state's breach-notification law: a business must now notify affected Californians within 30 calendar days of discovering a breach of their personal information. Before, the law required notice "without unreasonable delay" but set no fixed number of days. Delay is allowed for law-enforcement needs or to determine the breach's scope and restore the system, according to the bill text and The National Law Review. Law-firm coverage in JD Supra says the rule took effect January 1, 2026.

That clock applies only if personal information was actually breached; a compromised print server doesn't trigger it automatically. If yours handled customer or employee data, ask counsel early, and check what your cyber insurance policy expects after an incident.

What to do now

  1. Find out whether you run PaperCut. Ask your copier dealer or IT provider this week: "Do we run PaperCut NG or MF, or any print-management server, anywhere?" Get the version number in writing.
  2. Take the admin interface off the internet. If the PaperCut Application Server can be reached from the public internet, restrict web access to trusted IP addresses with firewall rules or network access controls. That's PaperCut's own first instruction, even if you've seen nothing suspicious.
  3. Patch versions 24, 25 and 26 now. Apply PaperCut's latest emergency patch for your version line.
  4. Upgrade version 23 or older. There is no patch for these versions. Schedule the upgrade to 24, 25 or 26 immediately, and keep the server isolated until it's done.
  5. Look for unexpected remote-access tools. Have IT check the server for a Windows service named "Remote Access Service" running SimpleService.exe, an AnyDesk install nobody authorized, and the other indicators listed in PaperCut's advisory.
  6. Treat any finding as an incident. Preserve logs, call your IT provider and cyber insurer, and talk to counsel about California's notification rules.
  7. Patch print servers within days, the same as firewalls and remote-access software.

Not sure whether PaperCut, or any print-management software, is running in your office? Book a free virtual consultation and we'll help you find out what's installed, which version it is, and whether it can be reached from the internet.

Update (September 30, 2026)

The fixes have moved on. On September 1, PaperCut released a third emergency patch that fixed two problems the earlier patches caused (broken SAML single sign-on and legacy Microsoft SQL Server drivers for external card lookup), according to PaperCut's advisory, Arctic Wolf and eSentire. PaperCut then shipped fully tested maintenance releases 26.0.5, 25.0.13 and 24.1.10, which replace all the emergency patches; it advises anyone on an emergency-patch build to move to one, per PaperCut's release history and The Hacker News. PaperCut says that if you use an external database for card or ID lookup, it must be reconfigured after upgrading. Version 23 and earlier still have no fix.

The attacks also grew: threat-intelligence firm GreyNoise documented a campaign that compromised at least 440 PaperCut NG/MF instances at 395 organizations in 48 countries, as Help Net Security and SecurityWeek reported. If your server was internet-reachable before you patched, have it checked for compromise, not just updated.

Frequently asked questions

What are the PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078?
They are two flaws in PaperCut NG and MF print-management software. CVE-2026-81578 is an authentication bypass in the web management interface, and CVE-2026-82078 is a critical unsafe class-loading flaw in its database connection utilities. Chained, they let an unauthenticated attacker run code on the server using only its IP address or hostname.
Is there a patch for PaperCut version 23?
No. PaperCut says there are no emergency patches or maintenance releases for PaperCut NG or MF version 23 or earlier. Offices on those versions need to upgrade to a supported version line, 24, 25 or 26, and until then should keep the server's admin interface off the internet and limited to trusted addresses.
How can I tell if my office uses PaperCut?
Ask your copier dealer or IT provider directly whether you run PaperCut NG, PaperCut MF or any print-management server, and get the version number. Clues include badge-release printing, print quotas, per-client print cost reports, and a server your copiers report to. Because it may have been set up during a copier installation, owners may not recognize the name.
Does California require breach notification if a print server is hacked?
Only if personal information was breached. Under SB 446, in effect since January 1, 2026 according to law-firm coverage, a business must notify affected Californians within 30 calendar days of discovering a breach of their personal information. A compromised print server doesn't automatically trigger that, so have counsel assess what data was exposed.

Sources

Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.

  1. URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) — PaperCut, 2026-08-27
  2. PaperCut NG/MF vulnerabilities exploited in zero-day attacks — Help Net Security, 2026-08-27
  3. Print management outfit PaperCut is under 0-day attack, and it's drawing customers' blood — The Register, 2026-08-28
  4. PaperCut Releases Emergency Patch for Exploited Zero-Day — SecurityWeek
  5. PaperCut NG/MF zero-day (CVE-2026-81578, CVE-2026-82078): active exploitation underway — watchTowr
  6. CVE-2026-81578 and CVE-2026-82078: PaperCut NG/MF vulnerabilities — Arctic Wolf
  7. PaperCut issues emergency patches as threat actors chain vulnerabilities — Cybersecurity Dive
  8. CISA Adds Two Known Exploited Vulnerabilities to Catalog — CISA, 2026-08-31
  9. Known Exploited Vulnerabilities Catalog: CVE-2026-82078 — CISA, 2026-08-31
  10. Attackers plant remote access tools on compromised PaperCut servers — Help Net Security, 2026-08-31
  11. PaperCut Exploitation Escalates to Active Intrusions — SecurityWeek
  12. PaperCut NG/MF actively exploited — Huntress
  13. PaperCut security advisory (AV26-858) — Canadian Centre for Cyber Security, 2026-08-28
  14. PaperCut releases second emergency patch for exploited flaws — BleepingComputer
  15. Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — The Hacker News, 2026-08
  16. U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog — Security Affairs
  17. SB 446 bill text and status (Chapter 319, Statutes of 2025) — California Legislative Information, 2025-10-03
  18. 30 Day Deadline for Data Breach Notifications Set in California — The National Law Review
  19. Prepare for California's 2026 Data Breach Law's Notice Requirement — JD Supra
  20. PaperCut discloses zero-day vulnerabilities CVE-2026-82078 and CVE-2026-81578 — eSentire
  21. PaperCut NG/MF 26.0 release history — PaperCut
  22. PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws — The Hacker News, 2026-09
  23. Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF — GreyNoise
  24. AI agents exploited PaperCut flaws to breach 395 organizations — Help Net Security, 2026-09-11
  25. PaperCut Flaws Exploited in AI-Powered Attacks — SecurityWeek

About Valley Printer Pros Team

Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.

Get Expert Advice

Related Articles

security
Blurred PDF Invoices With QR Codes: HP Wolf's Quishing Warning

On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.

Sep 28, 20266 min read
security
September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed

Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.

Sep 14, 20267 min read
security
Sharp and Toshiba Copier Flaws: Turn On User Authentication

On July 31, Sharp and Toshiba Tec disclosed three flaws in their office MFPs, and NIST's vulnerability database published them August 3. The most practical one: affected models built for markets outside Japan, including the US, shipped with user authentication turned off. Turn it on, and ask your dealer for the firmware that fixes the other two.

Aug 10, 20268 min read

Need Help with Your Printer Decisions?

Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.