Attackers are actively exploiting two newly disclosed PaperCut NG/MF flaws — CVE-2026-81578 and CVE-2026-82078 — that chain authentication bypass into remote code execution on print-management servers. BleepingComputer notes PaperCut’s footprint: about 100 million users across 70,000+ organizations including enterprises, agencies, and schools. Exploit activity showed up in honeypots from August 29 UTC, and PaperCut has pushed emergency releases through “Release 3,” urging anyone with internet-facing application servers to install the latest even if earlier hotfixes were applied.
PaperCut has been a repeat ransomware initial-access favorite since 2023; this wave is the same lesson with new CVE numbers — patch edge-exposed print consoles first.