Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.
Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.
PaperCut Software released three sets of emergency patches to address the vulnerabilities on Thursday, Friday, and Tuesday, "to rush mitigations to customers who might not be able to remove their servers from the internet."
"The first release was an emergency mitigation. The next release added further hardening as we understood more," explained PaperCut CEO Chris Dance today. "We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon."











