PaperCut Alerts Users to Active Exploitation of Critical Vulnerabilities in Print Management Software

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The company behind a popular brand of printer management software, PaperCut, has issued an emergency advisory regarding critical vulnerabilities in its software, PaperCut NG and MF, which are currently being exploited by cybercriminals. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores exceeding 8.8 out of 10. According to reporting by The Record, the PaperCut Software security response team is treating this matter with the highest priority due to confirmed incidents affecting customers.

Urgent Recommendations for Users

PaperCut has urged its users to take immediate action by removing their servers from the public internet and restricting web access to trusted IP addresses. The company emphasized that users should ensure that the web interfaces of their PaperCut servers are not accessible from untrusted internet addresses, stating, “Take this action now, even if you have not observed suspicious activity.”

Evidence of Exploitation

Multiple cybersecurity firms, including Huntress, have confirmed evidence of exploitation, with at least two customers impacted by the ongoing campaign targeting these vulnerabilities. An initial patch released by PaperCut was found to be insufficient, prompting the company to collaborate with experts from Huntress and watchTwr to develop a more effective patch.

Historical Context and Threat Landscape

Jake Knott, head of threat intelligence at watchTowr, highlighted that previous vulnerabilities in PaperCut software have been exploited by ransomware gangs and opportunistic attackers to gain initial access to corporate environments. In 2023, U.S. law enforcement agencies warned that ransomware groups such as Bl00dy and Clop were actively exploiting PaperCut vulnerabilities, particularly in the education sector, as noted by the Cybersecurity and Infrastructure Security Agency (CISA).

As the situation develops, organizations using PaperCut software are advised to remain vigilant and implement the recommended security measures to mitigate potential risks.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Australian Authorities Arrest Two Alleged Members of Hacking Group TeamPCP Behind Global Supply-Chain Attacks

Authorities in Australia announced the arrest of two men linked to TeamPCP, a notorious hacking group responsible for a series of global supply-chain attacks...

UAE Phishing Protection Market Expected to Grow Significantly by 2028

The phishing protection market in the UAE is poised for significant growth, with projections indicating a robust expansion by 2028. This development is underscored...

Malicious object blocks on ICS computers drop to 19.15% in Q2 2026, lowest since 2022.

Declining Threats in Industrial Control Systems: A Q2 2026 Overview In a notable shift within the cybersecurity landscape, the percentage of Industrial Control Systems (ICS)...

Eighteen Chrome and Edge Extensions Discovered with Wallet-Stealing and Crypto-Draining Capabilities

Cybersecurity researchers have identified a group of 18 Google Chrome extensions and one Microsoft Edge extension that possess wallet secret stealing and cryptocurrency draining...