Executive Summary
Two critical zero-day vulnerabilities in PaperCut NG and MF print management software (CVE-2026-81578 and CVE-2026-82078) were actively exploited by threat actors in August 2026 for data theft attacks. The flaws can be chained to bypass authentication and achieve remote code execution on vulnerable servers used by over 100 million users across 70,000 organizations globally. PaperCut Software released three emergency patches within a week to address the vulnerabilities, but threat intelligence indicates attackers are exploiting these flaws to dump database tables and steal sensitive data from exposed servers. With over 800 PaperCut servers still exposed online and a history of ransomware groups targeting similar vulnerabilities, this incident highlights the critical risk posed by internet-facing print management infrastructure.
This incident underscores the growing trend of attackers targeting enterprise software zero-days for immediate data theft rather than prolonged persistence, reflecting the increasing sophistication and speed of modern threat actors in monetizing newly discovered vulnerabilities.
Why This Matters Now
Print management systems are often overlooked in security assessments despite processing sensitive documents daily. With threat actors increasingly targeting enterprise software zero-days and over 800 PaperCut servers remaining exposed globally, organizations must prioritize securing internet-facing infrastructure and implementing zero-trust segmentation to prevent lateral movement from compromised print servers.
Attack Path Analysis
Attackers exploited CVE-2026-81578 and CVE-2026-82078 in internet-facing PaperCut NG/MF servers to bypass authentication and achieve remote code execution. They escalated privileges through the compromised application context, moved laterally within the network infrastructure, established persistent command channels, and executed database theft operations targeting Derby databases for sensitive organizational data extraction.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-81578 and CVE-2026-82078 vulnerabilities in internet-facing PaperCut NG/MF print management servers to bypass authentication and gain initial access
Related CVEs
CVE-2026-81578
CVSS 9.8Authentication bypass vulnerability in PaperCut NG and MF print management software that can be chained with CVE-2026-82078 for remote code execution.
Affected Products:
PaperCut Software PaperCut NG – < Emergency Patch Release 3
PaperCut Software PaperCut MF – < Emergency Patch Release 3
Exploit Status:
exploited in the wildCVE-2026-82078
CVSS 9.1Remote code execution vulnerability in PaperCut NG and MF print management software that can be chained with CVE-2026-81578 to achieve full system compromise.
Affected Products:
PaperCut Software PaperCut NG – < Emergency Patch Release 3
PaperCut Software PaperCut MF – < Emergency Patch Release 3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Process Injection
Exploitation of Remote Services
Data from Local System
Data from Information Repositories
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Testing
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – ICT Risk Management
Control ID: Article 10
CISA ZTMM 2.0 – Application-Level Authentication
Control ID: Application Security
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Educational institutions face critical data theft risks from PaperCut zero-days, with widespread print management infrastructure exposing student records to ransomware groups and state-backed attackers.
Government Administration
State agencies using PaperCut print management are vulnerable to authentication bypass and remote code execution, enabling data exfiltration by Iranian APT groups and ransomware operators.
Health Care / Life Sciences
Healthcare organizations risk HIPAA violations through PaperCut vulnerabilities allowing database theft via Derby exploitation, compromising patient data and triggering compliance enforcement actions.
Financial Services
Financial institutions face regulatory scrutiny as PaperCut flaws enable lateral movement and data exfiltration, threatening PCI compliance and exposing sensitive financial records to cybercriminals.
Sources
- Recently patched PaperCut zero-days used in data theft attackshttps://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/Verified
- Security Bulletin: 27 Aug 2026 - Urgent Security Advisoryhttps://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/Verified
- CVE-2026-81578 - Authentication Bypass Vulnerabilityhttps://nvd.nist.gov/vuln/detail/cve-2026-81578Verified
- CVE-2026-82078 - Remote Code Execution Vulnerabilityhttps://nvd.nist.gov/vuln/detail/cve-2026-82078Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this PaperCut vulnerability exploitation by limiting lateral movement paths and reducing the blast radius of database access through network segmentation and east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise of PaperCut servers would likely still occur, but CNSF visibility would constrain attacker discovery of internal network topology and reachable assets from the compromised position.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation within the PaperCut application would likely remain possible, but zero trust segmentation may limit the scope of accessible resources and constrain cross-service privilege inheritance.
Control: East-West Traffic Security
Mitigation: Lateral movement to database systems and file repositories would likely be significantly constrained through microsegmentation policies that restrict east-west communication paths between application and data tiers.
Control: Multicloud Visibility & Control
Mitigation: Command and control channel establishment would likely face detection and potential disruption through multicloud visibility monitoring of anomalous communication patterns and unauthorized external connections.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration operations would likely face significant constraints through controlled egress policies that limit outbound data volumes and restrict unauthorized external communication channels from database-connected systems.
Organizational data exposure would likely be reduced in scope through segmentation controls, potentially limiting access to isolated database subsets rather than comprehensive organizational records across all connected systems.
Impact at a Glance
Affected Business Functions
- Document Management and Print Services
- Administrative Operations
- Data Processing and Storage
- Network Infrastructure Services
Estimated downtime: 3 days
Estimated loss: N/A
Database tables containing sensitive organizational data accessed via Derby database exploitation. Potential exposure includes user credentials, print logs, document metadata, and system configuration data from affected PaperCut installations across educational institutions, state agencies, and corporate environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate print management servers from critical database systems and limit lateral movement potential
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts from compromised application servers
- • Enable Multicloud Visibility & Control to monitor anomalous database access patterns and repeated malformed requests targeting application vulnerabilities
- • Implement Inline IPS (Suricata) to detect and block known exploit patterns for CVE-2026-81578 and CVE-2026-82078 exploitation attempts
- • Deploy Encrypted Traffic (HPE) controls to secure data in transit and prevent clear-text database dump exfiltration during compromise scenarios



