PaperCut Alerts Users to Active Exploitation of Critical Vulnerabilities in Print Management Software

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

The company behind a popular brand of printer management software, PaperCut, has issued an emergency advisory regarding critical vulnerabilities in its software, PaperCut NG and MF, which are currently being exploited by cybercriminals. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores exceeding 8.8 out of 10. According to reporting by The Record, the PaperCut Software security response team is treating this matter with the highest priority due to confirmed incidents affecting customers.

Urgent Recommendations for Users

PaperCut has urged its users to take immediate action by removing their servers from the public internet and restricting web access to trusted IP addresses. The company emphasized that users should ensure that the web interfaces of their PaperCut servers are not accessible from untrusted internet addresses, stating, “Take this action now, even if you have not observed suspicious activity.”

Evidence of Exploitation

Multiple cybersecurity firms, including Huntress, have confirmed evidence of exploitation, with at least two customers impacted by the ongoing campaign targeting these vulnerabilities. An initial patch released by PaperCut was found to be insufficient, prompting the company to collaborate with experts from Huntress and watchTwr to develop a more effective patch.

Historical Context and Threat Landscape

Jake Knott, head of threat intelligence at watchTowr, highlighted that previous vulnerabilities in PaperCut software have been exploited by ransomware gangs and opportunistic attackers to gain initial access to corporate environments. In 2023, U.S. law enforcement agencies warned that ransomware groups such as Bl00dy and Clop were actively exploiting PaperCut vulnerabilities, particularly in the education sector, as noted by the Cybersecurity and Infrastructure Security Agency (CISA).

As the situation develops, organizations using PaperCut software are advised to remain vigilant and implement the recommended security measures to mitigate potential risks.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean Threat Actor Jade Sleet Compromises Indian IT Provider Using FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been linked to the compromise of a smaller Indian IT services organization, underscoring the...

Seclore Enhances Data-Centric Security Solutions Across Middle East, Turkey, and Africa

Seclore Expands Data-Centric Security Solutions Across META Seclore has unveiled significant advancements in its data-centric security solutions during GISEC Global 2026, focusing on the Middle...

AI’s Impact on Cybersecurity: Microsoft Highlights Evolving Threats and Security Fundamentals

The integration of artificial intelligence (AI) into cybersecurity has fundamentally altered the threat landscape, presenting both new challenges and opportunities for organizations. As cyberattackers...

Cochin Shipyard lays keel for Indian Navy’s first Next Generation Missile Vessel

The keel laying ceremony of the first Next Generation Missile Vessel (NGMV) for the Indian Navy was held on September 18, 2026. This milestone...