PaperCut Alerts Users to Active Exploitation of Critical Vulnerabilities in Print Management Software

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The company behind a popular brand of printer management software, PaperCut, has issued an emergency advisory regarding critical vulnerabilities in its software, PaperCut NG and MF, which are currently being exploited by cybercriminals. The vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, have severity scores exceeding 8.8 out of 10. According to reporting by The Record, the PaperCut Software security response team is treating this matter with the highest priority due to confirmed incidents affecting customers.

Urgent Recommendations for Users

PaperCut has urged its users to take immediate action by removing their servers from the public internet and restricting web access to trusted IP addresses. The company emphasized that users should ensure that the web interfaces of their PaperCut servers are not accessible from untrusted internet addresses, stating, “Take this action now, even if you have not observed suspicious activity.”

Evidence of Exploitation

Multiple cybersecurity firms, including Huntress, have confirmed evidence of exploitation, with at least two customers impacted by the ongoing campaign targeting these vulnerabilities. An initial patch released by PaperCut was found to be insufficient, prompting the company to collaborate with experts from Huntress and watchTwr to develop a more effective patch.

Historical Context and Threat Landscape

Jake Knott, head of threat intelligence at watchTowr, highlighted that previous vulnerabilities in PaperCut software have been exploited by ransomware gangs and opportunistic attackers to gain initial access to corporate environments. In 2023, U.S. law enforcement agencies warned that ransomware groups such as Bl00dy and Clop were actively exploiting PaperCut vulnerabilities, particularly in the education sector, as noted by the Cybersecurity and Infrastructure Security Agency (CISA).

As the situation develops, organizations using PaperCut software are advised to remain vigilant and implement the recommended security measures to mitigate potential risks.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...