Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut customer confirmed compromise incidents

Incident
First reported
Last updated
Happening score
H score 41
2 unique sources, 4 articles

Summary

Hide ▲

PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software. PaperCut released emergency patches for v25 and v26 and urged operators of Internet-exposed Application Servers to restrict access to trusted IP addresses immediately. The company shared indicators of compromise tied to suspicious activity from pc-app.exe and server.log files that are missing, truncated, or deleted. The investigation is ongoing, and PaperCut has not identified the flaw, the attackers, or any post-compromise actions.

Related Happenings

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
H score53 First: 05.09.2026 10:31 Last: 05.09.2026 10:31 Sources 1

About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave
H score56 First: 01.09.2026 20:53 Last: 01.09.2026 20:53 Sources 1

About this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability
H score53 First: 28.08.2026 20:12 Last: 28.08.2026 20:12 Sources 1

How related: PaperCut has now shared technical details and CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578.

About this happening: PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...

Latest development: 10.09.2026 14:41

A suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability
H score53 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

About this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release
H score51 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: On Friday, PaperCut released Emergency Patch Release 2, an updated security fix that includes additional hardening developed after further analysis with its internal security team and researchers at Huntress and watchTowr.

About this happening: PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...

Latest development: 01.09.2026 10:48

Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.

Timeline

  1. 01.09.2026 10:48 1 articles · 9d ago

    PaperCut NG/MF servers face data theft via CVE-2026-81578 and CVE-2026-82078

    Victim Impact Update

    Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).

    Show sources
  2. 28.08.2026 22:08 1 articles · 12d ago

    PaperCut releases Emergency Patch Release 2 for actively exploited NG/MF flaws

    Mitigation Patch Update

    PaperCut released Emergency Patch Release 2 for PaperCut NG/MF after researchers and watchTowr found multiple ways to bypass the initial fix for CVE-2026-82078 and CVE-2026-81578. The updated advisory says the flaws can be chained for authentication bypass and remote code execution on vulnerable servers, and it urges customers to install Release 2, upgrade Site Servers and secondary/print servers, restrict web access to trusted IP addresses, and look for post-exploitation signs such as pc-app.exe activity and missing or truncated server.log files.

    Show sources
  3. 27.08.2026 19:31 3 articles · 13d ago

    PaperCut warns of zero-day exploitation in NG and MF and releases emergency patches

    Initial Disclosure

    PaperCut says hackers are actively exploiting a zero-day in all versions of PaperCut NG and PaperCut MF, confirms customer incidents, shares indicators of compromise including suspicious activity from the legitimate pc-app.exe process and modified, deleted, or missing server.log files, and releases emergency patches for public-facing PaperCut NG/MF servers while urging administrators to restrict Internet-exposed Application Servers to trusted IP addresses.

    Show sources