Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have escalated, with threat actors shifting from reconnaissance to hands-on-keyboard activity.
PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August 27. It later emerged that threat actors have been chaining two flaws in their attacks.
The vulnerabilities are tracked as CVE-2026-82078 and CVE-2026-81578, and they can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances.
The vendor quickly rolled out two emergency patches — one after the first was bypassed — and is working on an official release that addresses both vulnerabilities.
In the meantime, attacks are escalating, according to exposure management firm WatchTowr, whose researchers have been monitoring the situation.











