PaperCut warns of hackers using printer management software flaw in attacks
The company behind a popular brand of printer management software warned customers of a new vulnerability currently being used by cybercriminals.
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation. The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the company said.
PaperCut’s software is used widely across large organizations like universities, corporations and governments. Organizations use PaperCut software to manage a variety of printer brands including Canon, Epson, Xerox, Brother and more.
The company urged customers to remove their servers from the public internet and restrict web access to only trusted IP addresses. Customers need to take every step to ensure PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.
“Take this action now, even if you have not observed suspicious activity,” PaperCut said.
In the security advisory issued on Thursday, the company said it used information provided by a university customer’s security team to reproduce the vulnerability and develop a fix.
Multiple cybersecurity companies confirmed evidence of exploitation including Huntress, which said it has at least two customers impacted by the campaign targeting the bugs.
An initial patch issued by PaperCut did not sufficiently address the vulnerabilities and the company said it worked with experts from Huntress and watchtwr to create a new patch released on Friday.
Jake Knott, head of threat intelligence at watchTowr, noted that previous PaperCut vulnerabilities were used by ransomware gangs and opportunistic attackers to gain initial access.
“PaperCut is a prime target for attackers of every motivation, as not only is it an internet-facing pivot into a corporate environment, but it is a sensitive information treasure trove if printed documents can be stored and exfiltrated,” Knott said.
In 2023, U.S. law enforcement agencies warned that ransomware gangs like Bl00dy and Clop were exploiting PaperCut bugs. The Cybersecurity and Infrastructure Security Agency (CISA) specifically issued an advisory for K-12 schools that said the education sector is particularly exposed to PaperCut vulnerabilities.
Microsoft said an Iranian state-backed group known for attacking critical infrastructure exploited the same bug that year in multiple attacks.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



