PaperCut Exploitation Escalates to Active Intrusions

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have escalated, with threat actors shifting from reconnaissance to hands-on-keyboard activity.

PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August 27. It later emerged that threat actors have been chaining two flaws in their attacks.

The vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578, and they can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.

The vendor quickly rolled out two emergency patches — one after the first was bypassed — and is working on an official release that addresses both vulnerabilities.

In the meantime, attacks are escalating, according to exposure management firm WatchTowr, whose researchers have been monitoring the situation.

“Activity has significantly evolved, and it did so quickly — we are no longer seeing purely exploratory probes to identify vulnerable...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more