Hackers are actively exploiting a PaperCut NG MF zero-day vulnerability affecting all versions of the print management software, with PaperCut confirming customer incidents and urging organisations to act immediately. The flaw is not a single bug but a chained pair: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, a pre-authentication remote code execution vulnerability exploiting unsafe dynamic class loading, according to Tech Insider.
PaperCut’s security response team published an urgent advisory describing active exploitation of vulnerabilities affecting both PaperCut NG and PaperCut MF. ‘We are aware of confirmed customer incidents and are treating this matter with the highest priority,’ the advisory reads. The company says its team reproduced the vulnerability using information provided by a university customer, though it has stopped short of disclosing technical specifics about exactly how the flaw is being exploited in the wild.
What the Chained Flaws Actually Do
The authentication bypass component, CVE-2026-81578, targets the PaperCut NG/MF web management interface and carries a CVSS severity rating of 8.8, classified as high, according to BleepingComputer. That rating alone would make it worth patching promptly; paired with CVE-2026-82078, which allows pre-authenticated remote code execution, the combination gives an attacker a path from the public internet into a server without needing valid credentials first. It is the kind of chained exploit that ransomware operators tend to weaponise quickly.
Emergency patches for PaperCut NG and PaperCut MF versions 25 and 26 were released on 28 August 2026 at 02:10 AEST, according to Rapid7. PaperCut describes the patch as an emergency release specifically for customers with public-facing servers who cannot implement other mitigating controls in the interim. For everyone else, the company’s immediate guidance is consistent: use firewall rules or network access controls to restrict the web interface to trusted IP addresses only.
Indicators of Compromise and the PaperCut NG MF Zero-Day Investigation
PaperCut has shared indicators of compromise for administrators checking whether their servers have already been hit. Suspicious activity from the legitimate pc-app.exe process is one signal. Administrators should also examine server.log files: modifications, deletions, or missing logs are cause for concern, as are specific errors including ‘ERROR No suitable driver found for jdbc:no:x’ and ‘ERROR DatabaseUtils, Database error looking up cardID: VALUES CAST’ (reproduced here from the advisory; the original uses a formatting convention PaperCut has documented).
There is a catch, though. PaperCut explicitly warns that a clean bill of health from these indicators does not confirm a server is uncompromised. Attackers may already have covered their tracks. The company says it will keep updating its advisory with additional indicators and remediation guidance as the investigation progresses.
At this point, PaperCut has not disclosed who is behind the current attacks, what post-compromise activity is taking place, or whether data is being exfiltrated.
A Target With History
This is not the first time PaperCut’s software has drawn serious attention from threat actors. In April 2023, attackers began exploiting CVE-2023-27350, a critical vulnerability that allowed unauthenticated attackers to bypass authentication and remotely execute code. Microsoft linked a portion of those attacks to the Clop ransomware operation, which used vulnerable PaperCut servers for initial access to company networks rather than to steal documents directly from print archives (Clop confirmed as much to BleepingComputer at the time). Separately, Microsoft observed intrusions that led to LockBit ransomware deployments.
The CVE-2023-27350 exploitation broadened further still: Microsoft reported that Iranian state-backed hacking groups also picked up the vulnerability, and CISA and the FBI issued a joint advisory in May 2023 warning that the Bl00dy Ransomware Gang was targeting the education sector via the same flaw. That pattern of initial exploitation by one group rapidly giving way to opportunistic adoption by others is a reasonable backdrop for how the current PaperCut NG MF zero-day campaign may develop if patches are not applied promptly.
PaperCut has said it will continue updating its advisory. For administrators still assessing exposure, the company’s emergency patch for versions 25 and 26, released 28 August 2026, is the most direct remediation available right now.

