Recently patched PaperCut zero-days used in data theft attacks
Two zero-day vulnerabilities in PaperCut's print management software, recently patched, are now being exploited for data theft. Attackers are chaining the flaws to bypass authentication and steal data from vulnerable servers.
Intelligence analysis by Gemini 2.5 Flash Lite

Exploits for recently patched zero-day vulnerabilities in PaperCut NG and MF print management software are actively being used for data theft. Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to bypass authentication and exfiltrate data, rather than pursuing remote code execution.
Imagine your school uses a special printer system called PaperCut to manage printing. Bad guys found a secret way to sneak into this system, not to break it, but to steal information stored inside, like a sneaky librarian taking books from a shelf.
Analysis
CVE-2026-81578 and CVE-2026-82078
The recent discovery and exploitation of two zero-day vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, in PaperCut's widely used NG and MF print management software have raised significant security concerns. These vulnerabilities, which were patched by PaperCut Software in late August 2026, can be chained together to achieve a critical outcome: bypassing authentication and gaining unauthorized access to the servers. This allows attackers to execute code remotely, a common precursor to more severe intrusions.
However, the threat intelligence shared by Defused indicates a shift in attacker tactics. Instead of solely focusing on remote code execution (RCE), threat actors are leveraging the authentication bypass to hijack PaperCut's external user-lookup functionality. This specific technique is being used to dump database tables, particularly through the Derby database, indicating a primary objective of data exfiltration rather than system compromise for other malicious purposes.
PaperCut Software
PaperCut Software's print management solutions are deployed across a vast user base, estimated at 100 million users in over 70,000 organizations globally. This includes a diverse range of entities, from large corporations and government agencies to educational institutions. The widespread adoption of PaperCut software means that any security vulnerability within its systems has the potential for a broad impact. The company's swift release of emergency patches demonstrates an awareness of the severity, but the fact that these zero-days were exploited before a patch was available, and are now being actively abused for data theft, underscores the persistent challenges in securing such widely distributed software.
The company has provided indicators of compromise to aid defenders, but has not yet attributed the attacks to specific threat actors or detailed the full scope of post-compromise activities. This lack of attribution leaves organizations to remain vigilant against potential ongoing threats, even after applying the provided patches.
Data Theft Attacks
The current wave of attacks specifically targets data theft, a concerning development that deviates from some previous PaperCut exploits. While past vulnerabilities, such as CVE–2023–27350 and CVE–2023–27351, were chained by ransomware gangs like LockBit and Clop, and state-backed groups like MuddyWater and APT35, to gain initial access and potentially deploy ransomware or conduct espionage, the current exploitation focuses on exfiltrating data directly. This is achieved by dumping database tables via the Derby database, a method that can yield sensitive information without necessarily requiring full system control.
This focus on data theft is particularly alarming for organizations that store sensitive information within or accessible through their PaperCut systems. The ability for attackers to bypass authentication and directly access and exfiltrate data means that even systems that might have been considered less critical for RCE might now be prime targets for information harvesting. The ongoing exploitation, even after patching, suggests that many organizations may not have applied the patches promptly, leaving them vulnerable to these data-stealing operations.
Key points
- Two zero-day vulnerabilities (CVE-2026-81578, CVE-2026-82078) in PaperCut NG/MF software have been patched.
- These vulnerabilities are being actively exploited in data theft attacks, not just for remote code execution.
- Attackers are chaining the flaws to bypass authentication and dump database tables.
- PaperCut software is used by millions of users across tens of thousands of organizations globally.
- The exploitation highlights the ongoing risk of zero-day attacks even after patches are released.
The rapid patching of these zero-day vulnerabilities by PaperCut Software, coupled with the release of indicators of compromise, provides organizations with the necessary tools to quickly secure their systems. If organizations act swiftly to apply these patches and implement monitoring, the impact of these specific attacks can be significantly mitigated, preventing widespread data breaches.
Despite the patches, the active exploitation in the wild suggests that many organizations may be slow to update their PaperCut systems, leaving them vulnerable to ongoing data theft. The sophisticated nature of chaining vulnerabilities and targeting data exfiltration indicates that attackers will continue to seek out and exploit such weaknesses in widely used software.



