RECENT vulnerabilities in PaperCut NG/MF solutions have led to a significant escalation in cyberattacks. Threat actors exploited two zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578) allowing remote code execution and bypassing authentication. PaperCut issued emergency patches, but attacks have progressed to hands-on exploitation by attackers, according to experts from WatchTowr.
The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies to act quickly. Over 1,000 PaperCut instances are reportedly exposed online, necessitating immediate incident response measures for affected organizations.