Executive Summary

Two critical zero-day vulnerabilities in PaperCut NG and MF print management software (CVE-2026-81578 and CVE-2026-82078) were actively exploited by threat actors in August 2026 for data theft attacks. The flaws can be chained to bypass authentication and achieve remote code execution on vulnerable servers used by over 100 million users across 70,000 organizations globally. PaperCut Software released three emergency patches within a week to address the vulnerabilities, but threat intelligence indicates attackers are exploiting these flaws to dump database tables and steal sensitive data from exposed servers. With over 800 PaperCut servers still exposed online and a history of ransomware groups targeting similar vulnerabilities, this incident highlights the critical risk posed by internet-facing print management infrastructure.

This incident underscores the growing trend of attackers targeting enterprise software zero-days for immediate data theft rather than prolonged persistence, reflecting the increasing sophistication and speed of modern threat actors in monetizing newly discovered vulnerabilities.

Why This Matters Now

Print management systems are often overlooked in security assessments despite processing sensitive documents daily. With threat actors increasingly targeting enterprise software zero-days and over 800 PaperCut servers remaining exposed globally, organizations must prioritize securing internet-facing infrastructure and implementing zero-trust segmentation to prevent lateral movement from compromised print servers.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should immediately apply the latest emergency patches, remove PaperCut servers from internet exposure where possible, and implement zero-trust network segmentation to limit lateral movement from compromised print infrastructure.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this PaperCut vulnerability exploitation by limiting lateral movement paths and reducing the blast radius of database access through network segmentation and east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise of PaperCut servers would likely still occur, but CNSF visibility would constrain attacker discovery of internal network topology and reachable assets from the compromised position.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation within the PaperCut application would likely remain possible, but zero trust segmentation may limit the scope of accessible resources and constrain cross-service privilege inheritance.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement to database systems and file repositories would likely be significantly constrained through microsegmentation policies that restrict east-west communication paths between application and data tiers.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control channel establishment would likely face detection and potential disruption through multicloud visibility monitoring of anomalous communication patterns and unauthorized external connections.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration operations would likely face significant constraints through controlled egress policies that limit outbound data volumes and restrict unauthorized external communication channels from database-connected systems.

Impact (Mitigations)

Organizational data exposure would likely be reduced in scope through segmentation controls, potentially limiting access to isolated database subsets rather than comprehensive organizational records across all connected systems.

Impact at a Glance

Affected Business Functions

  • Document Management and Print Services
  • Administrative Operations
  • Data Processing and Storage
  • Network Infrastructure Services
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Database tables containing sensitive organizational data accessed via Derby database exploitation. Potential exposure includes user credentials, print logs, document metadata, and system configuration data from affected PaperCut installations across educational institutions, state agencies, and corporate environments.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate print management servers from critical database systems and limit lateral movement potential
  • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from compromised application servers
  • Enable Multicloud Visibility & Control to monitor anomalous database access patterns and repeated malformed requests targeting application vulnerabilities
  • Implement Inline IPS (Suricata) to detect and block known exploit patterns for CVE-2026-81578 and CVE-2026-82078 exploitation attempts
  • Deploy Encrypted Traffic (HPE) controls to secure data in transit and prevent clear-text database dump exfiltration during compromise scenarios

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image