PaperCut warns of hackers using printer management software flaw in attacks
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
The company behind a popular brand of printer management software warned customers of a new vulnerability currently being used by cybercriminals.
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation. The company released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the company said.
Source: https://therecord.media/papercut-warns-of-hackers-using-printer-management-vulnerabilities
Related breach coverage
- Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch2026-08-30
PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evidence […]
- U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog2026-09-01
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]
- SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs2026-09-02
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that […]
- Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw2026-08-21
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code execution and was […]