The company behind a popular brand of printer management software, PaperCut, has issued an emergency advisory regarding critical vulnerabilities in its software, PaperCut NG and MF, which are currently being exploited by cybercriminals. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores exceeding 8.8 out of 10. According to reporting by The Record, the PaperCut Software security response team is treating this matter with the highest priority due to confirmed incidents affecting customers.
Urgent Recommendations for Users
PaperCut has urged its users to take immediate action by removing their servers from the public internet and restricting web access to trusted IP addresses. The company emphasized that users should ensure that the web interfaces of their PaperCut servers are not accessible from untrusted internet addresses, stating, “Take this action now, even if you have not observed suspicious activity.”
Evidence of Exploitation
Multiple cybersecurity firms, including Huntress, have confirmed evidence of exploitation, with at least two customers impacted by the ongoing campaign targeting these vulnerabilities. An initial patch released by PaperCut was found to be insufficient, prompting the company to collaborate with experts from Huntress and watchTwr to develop a more effective patch.
Historical Context and Threat Landscape
Jake Knott, head of threat intelligence at watchTowr, highlighted that previous vulnerabilities in PaperCut software have been exploited by ransomware gangs and opportunistic attackers to gain initial access to corporate environments. In 2023, U.S. law enforcement agencies warned that ransomware groups such as Bl00dy and Clop were actively exploiting PaperCut vulnerabilities, particularly in the education sector, as noted by the Cybersecurity and Infrastructure Security Agency (CISA).
As the situation develops, organizations using PaperCut software are advised to remain vigilant and implement the recommended security measures to mitigate potential risks.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



