PaperCut Exploitation Escalates to Active Intrusions

Summary: CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

PaperCut Attacks Escalate From Scanning to Active Network Intrusions

The exploitation of two critical vulnerabilities affecting PaperCut NG and MF has rapidly moved beyond automated internet scanning. Security researchers are now observing attackers actively interacting with compromised systems, deploying remote-access tooling and attempting to use vulnerable PaperCut servers as entry points into internal networks.

The escalation comes only days after PaperCut first warned customers on August 27 about an actively exploited zero-day vulnerability. Further investigation revealed that attackers were chaining CVE-2026-82078 and CVE-2026-81578, allowing unauthenticated attackers to bypass authentication and ultimately achieve remote code execution on vulnerable PaperCut installations.

Attackers are moving beyond automated exploitation

The most important development is the change in attacker behavior. Exposure-management company WatchTowr initially observed activity resembling reconnaissance and automated attempts to identify vulnerable servers. That activity has since evolved into what researchers describe as hands-on-keyboard intrusions, where human operators interact directly with systems after compromising them.

That distinction significantly raises the risk. Automated scanners may simply identify vulnerable infrastructure or deploy generic payloads. A human operator can instead examine the environment, search for credentials, identify valuable systems and determine how the compromised PaperCut server can be used to move deeper into the organization.

WatchTowr says some of the observed activity appears specifically designed to enable external-to-internal network pivoting. Attackers have also deployed in-memory payloads protected so that only the original operator can interact with them, behavior that researchers say resembles the methods used by initial-access brokers and other financially motivated intrusion groups.

PaperCut’s updated indicators of compromise reinforce that assessment, showing attackers deploying remote-access tools on affected systems.

Two vulnerabilities are being chained

The attacks involve vulnerabilities affecting PaperCut NG and PaperCut MF, products widely used by organizations to centrally manage printing infrastructure.

CVE-2026-82078 and CVE-2026-81578 can be chained to move from an unauthenticated position to remote code execution. That combination is particularly dangerous on an internet-facing management server because an attacker does not need valid credentials before beginning the compromise.

PaperCut responded with an emergency patch, but researchers subsequently demonstrated that the initial mitigation could be bypassed. The company therefore issued a second emergency patch and is working on an official software release addressing both vulnerabilities.

The sequence illustrates how difficult zero-day response can become once exploitation begins before defenders have a mature fix. Vendors must investigate the vulnerability, develop mitigations and distribute them while attackers simultaneously reverse-engineer those defenses and search for ways around them.

More than 1,000 PaperCut systems remain exposed

The potential attack surface is substantial. ShadowServer data cited by SecurityWeek shows that more than 1,000 PaperCut NG/MF instances remain directly exposed to the internet.

Internet exposure is particularly important because PaperCut servers can occupy a useful position inside corporate networks. Print-management infrastructure may interact with directory services, authentication systems, endpoints and other internal resources. Compromising such a server can therefore provide attackers with something considerably more valuable than control of the printing environment itself: a foothold from which they can investigate the rest of the network.

This is also why the escalation toward interactive intrusions matters. Attackers are apparently no longer interested only in proving that vulnerable PaperCut servers can be compromised. They are examining what those servers can provide access to next.

CISA adds both vulnerabilities to its exploited list

The US Cybersecurity and Infrastructure Security Agency has now added CVE-2026-82078 and CVE-2026-81578 to its Known Exploited Vulnerabilities catalog, formally recognizing that the flaws are being used in real-world attacks.

US federal civilian agencies have been ordered to address the vulnerabilities by September 14.

The addition to the KEV catalog is especially relevant for private organizations as well. Although CISA’s remediation deadlines primarily apply to federal agencies, the catalog has become an important prioritization tool because inclusion confirms that exploitation is not merely theoretical.

For security teams managing large vulnerability backlogs, these PaperCut flaws should therefore move toward the top of remediation queues.

Patching may no longer be enough

Perhaps the most important warning from researchers is that organizations should not assume installing the latest patch automatically resolves the incident.

WatchTowr argues that an internet-exposed PaperCut server that remained unpatched during the recent exploitation window should potentially be treated as already compromised.

That changes the appropriate response.

Patching prevents attackers from exploiting the original vulnerabilities again, but it does not necessarily remove remote-access tools, in-memory payloads, stolen credentials or persistence mechanisms that may already exist on the server. An attacker who compromised the system before the patch was installed could therefore maintain access afterward.

Organizations with exposed systems need to examine PaperCut’s published indicators of compromise, review authentication and process activity, investigate unexpected outbound connections and determine whether attackers moved from the PaperCut host into other parts of the network.

Where evidence indicates compromise—or where sufficient logging does not exist to confidently exclude it—incident response may be more appropriate than simple vulnerability management.

PaperCut is becoming an initial-access opportunity

The incident follows a familiar pattern in modern enterprise attacks. A vulnerability appears in a widely deployed internet-facing product, automated scanners begin searching for exposed installations almost immediately, and successful compromises are subsequently handed over to human operators capable of turning initial access into a broader intrusion.

At that stage, the original vulnerability becomes only the beginning of the attack.

The critical question for defenders is no longer simply “Is our PaperCut server patched?” It becomes “Was someone already inside before we patched it?”

That distinction is particularly important now that researchers are seeing interactive exploitation and network-pivoting behavior. Organizations that exposed vulnerable PaperCut systems during the past several days should therefore consider the incident a potential compromise rather than treating it solely as another emergency patching exercise.

⁠Original report at SecurityWeek

Key facts

  • CISA has added CVE-2026-82078 to its KEV catalog
  • CISA has added CVE-2026-81578 to its KEV catalog
  • The vulnerabilities are associated with PaperCut software

Why it matters

The inclusion of these PaperCut vulnerabilities in CISA's KEV catalog signifies active exploitation and poses a direct threat to organizations utilizing the affected software. This designation mandates that federal agencies prioritize patching these vulnerabilities to mitigate risks of further intrusion and potential data breaches, serving as a critical alert for all users of PaperCut software.