securityaffairs.com 8/30/2026, 12:31:36 PM · external

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
Developing story vulnerability 5 articles tracked
PaperCut NG/MF zero‑day exploited (CVE-2026-81578, CVE-2026-82078)
CyberSIXT Evidence Panel
Primary Source huntress.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses ongoing attacks on PaperCut servers, with 47% of installations still using unpatched versions vulnerable to critical flaws. A recent report from Huntress confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-81578) is being actively exploited. This vulnerability allows attackers to execute actions without proper authentication, posing severe risks.

Attackers have been observed performing reconnaissance activities rather than launching full-scale attacks, leaving behind a forensic trail that can aid in defense. PaperCut's patching process was complicated, with emergency updates released rapidly, but many older versions still lack fixes, urging organizations to isolate their servers while awaiting solutions. It’s highlighted that evidence from log files should be preserved post-exploitation for investigation.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline