discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Recently patched PaperCut zero-days used in data theft attacks

Two zero-day vulnerabilities in PaperCut's print management software, recently patched, are now being exploited for data theft. Attackers are chaining the flaws to bypass authentication and steal data from vulnerable servers.

By Sergiu Gatlan·Sep 1·bleepingcomputer.com·3 min read

Intelligence analysis by Gemini 2.5 Flash Lite

Recently patched PaperCut zero-days used in data theft attacks
Image: bleepingcomputer.com

Exploits for recently patched zero-day vulnerabilities in PaperCut NG and MF print management software are actively being used for data theft. Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to bypass authentication and exfiltrate data, rather than pursuing remote code execution.

Why it matters

The active exploitation of these vulnerabilities in data theft attacks highlights the ongoing risk to organizations using PaperCut software, even after patches are released, underscoring the need for rapid patching and vigilant monitoring.

Imagine your school uses a special printer system called PaperCut to manage printing. Bad guys found a secret way to sneak into this system, not to break it, but to steal information stored inside, like a sneaky librarian taking books from a shelf.

Analysis

CVE-2026-81578 and CVE-2026-82078

The recent discovery and exploitation of two zero-day vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, in PaperCut's widely used NG and MF print management software have raised significant security concerns. These vulnerabilities, which were patched by PaperCut Software in late August 2026, can be chained together to achieve a critical outcome: bypassing authentication and gaining unauthorized access to the servers. This allows attackers to execute code remotely, a common precursor to more severe intrusions.

However, the threat intelligence shared by Defused indicates a shift in attacker tactics. Instead of solely focusing on remote code execution (RCE), threat actors are leveraging the authentication bypass to hijack PaperCut's external user-lookup functionality. This specific technique is being used to dump database tables, particularly through the Derby database, indicating a primary objective of data exfiltration rather than system compromise for other malicious purposes.

PaperCut Software

PaperCut Software's print management solutions are deployed across a vast user base, estimated at 100 million users in over 70,000 organizations globally. This includes a diverse range of entities, from large corporations and government agencies to educational institutions. The widespread adoption of PaperCut software means that any security vulnerability within its systems has the potential for a broad impact. The company's swift release of emergency patches demonstrates an awareness of the severity, but the fact that these zero-days were exploited before a patch was available, and are now being actively abused for data theft, underscores the persistent challenges in securing such widely distributed software.

The company has provided indicators of compromise to aid defenders, but has not yet attributed the attacks to specific threat actors or detailed the full scope of post-compromise activities. This lack of attribution leaves organizations to remain vigilant against potential ongoing threats, even after applying the provided patches.

Data Theft Attacks

The current wave of attacks specifically targets data theft, a concerning development that deviates from some previous PaperCut exploits. While past vulnerabilities, such as CVE–2023–27350 and CVE–2023–27351, were chained by ransomware gangs like LockBit and Clop, and state-backed groups like MuddyWater and APT35, to gain initial access and potentially deploy ransomware or conduct espionage, the current exploitation focuses on exfiltrating data directly. This is achieved by dumping database tables via the Derby database, a method that can yield sensitive information without necessarily requiring full system control.

This focus on data theft is particularly alarming for organizations that store sensitive information within or accessible through their PaperCut systems. The ability for attackers to bypass authentication and directly access and exfiltrate data means that even systems that might have been considered less critical for RCE might now be prime targets for information harvesting. The ongoing exploitation, even after patching, suggests that many organizations may not have applied the patches promptly, leaving them vulnerable to these data-stealing operations.

Key points

  • Two zero-day vulnerabilities (CVE-2026-81578, CVE-2026-82078) in PaperCut NG/MF software have been patched.
  • These vulnerabilities are being actively exploited in data theft attacks, not just for remote code execution.
  • Attackers are chaining the flaws to bypass authentication and dump database tables.
  • PaperCut software is used by millions of users across tens of thousands of organizations globally.
  • The exploitation highlights the ongoing risk of zero-day attacks even after patches are released.
The Upside

The rapid patching of these zero-day vulnerabilities by PaperCut Software, coupled with the release of indicators of compromise, provides organizations with the necessary tools to quickly secure their systems. If organizations act swiftly to apply these patches and implement monitoring, the impact of these specific attacks can be significantly mitigated, preventing widespread data breaches.

The Downside

Despite the patches, the active exploitation in the wild suggests that many organizations may be slow to update their PaperCut systems, leaving them vulnerable to ongoing data theft. The sophisticated nature of chaining vulnerabilities and targeting data exfiltration indicates that attackers will continue to seek out and exploit such weaknesses in widely used software.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityzero-daypapercutdata-theftvulnerabilitiescybersecurity

Author

Sergiu Gatlan

Intelligence analysis by

Gemini 2.5 Flash Lite

Published

Sep 1, 2026

Source

bleepingcomputer.com

Share

Topics

securityzero-daypapercutdata-theftvulnerabilitiescybersecurity

Related

More from this desk

Sep 1·thehackernews.com

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

A Russia-aligned group, UAC-0099, is using a new technique called GuardBreaker to trick AI security tools by embedding dangerous prompts into malware.

Sep 1·thehackernews.com

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Attackers are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, leading to credential harvesting and command-and-control activity.

Aug 31·bleepingcomputer.com

Cronos blockchain restarts after $74 million Tectonic exploit

Cronos blockchain network resumes trading after Tectonic exploit

Aug 31·bleepingcomputer.com

Microsoft Warns of TerminalFix Attacks Using Reverse Tunnels

Microsoft alerts about a new variant of ClickFix attacks that use fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands in Windows Terminal. The attacks lead to a multi-stage intrusion chain resulting in a reverse tunnel into the vict…