
CISA Issues Urgent Warning as PaperCut Zero-Day RCE Flaws Face Mass Exploitation in the Wild
CISA has added two critical PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078) to its Known Exploited Vulnerabilities catalog following reports of active remote code execution attacks.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-81578, CVE-2026-82078
- Source:
- CISA / CyberSIXT
- Read Time:
- 4 min
Executive Summary
On August 31, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) officially added two critical vulnerabilities affecting PaperCut NG and MF print management software to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, tracked as CVE-2026-81578 and CVE-2026-82078, are currently being exploited in the wild by unidentified threat actors to achieve unauthenticated remote code execution (RCE). The disclosure follows a surge in malicious activity targeting internet-facing print servers, primarily across North America and Europe. Organizations are urged to apply emergency patches immediately to prevent full system compromise.
Threat Analysis
The exploitation of these zero-day vulnerabilities represents a significant escalation in attacks against enterprise infrastructure. According to reports from CyberSIXT, the attack chain is highly efficient, allowing attackers to bypass standard security controls without any user interaction. The primary vector involves targeting the PaperCut web interface, which is frequently exposed to the public internet for remote print management. Once an instance is identified, threat actors utilize a two-stage approach: first bypassing authentication and then executing arbitrary commands with the privileges of the PaperCut service, which often runs with high-level system permissions.
Technical Details
The first vulnerability, CVE-2026-81578, is an authentication bypass flaw with a CVSS v3.1 score of 8.8. It resides in the web-based management component of PaperCut NG and MF. By sending specially crafted HTTP requests, an attacker can manipulate the application's session management logic to gain administrative access without providing valid credentials.
The second vulnerability, CVE-2026-82078, is a remote code execution flaw that is triggered once administrative access (or the aforementioned bypass) is achieved. This flaw allows the injection of malicious scripts into the server's processing queue. When combined, these vulnerabilities allow a completely unauthenticated remote attacker to take over the host operating system. Current telemetry suggests that approximately one thousand internet-facing instances remain vulnerable as of September 1, 2026.
Attribution Assessment
At this stage, the attribution remains unknown. However, the patterns of exploitation—characterized by rapid scanning and the deployment of persistent backdoors—align with the tactics of sophisticated cybercriminal groups or initial access brokers (IABs). There is currently no definitive evidence linking these attacks to specific nation-state APTs, though the high value of print servers as lateral movement hubs makes them an attractive target for espionage-focused actors. The speed at which these zero-days were weaponized following their discovery suggests a high level of technical proficiency among the attackers.
Implications
The compromise of a PaperCut server is a high-impact event. Print management systems often store sensitive documents in transit and maintain connections to active directory (AD) for user authentication. A successful breach allows attackers to harvest credentials, intercept confidential printed materials, and move laterally through the corporate network. Furthermore, because these servers are often overlooked in standard patch cycles compared to primary web servers or databases, they provide a resilient foothold for long-term persistence.
Recommendations
Encrygma Intelligence recommends the following immediate actions:
- Immediate Patching: Update PaperCut NG and MF to the latest security release (v26.1.3 or higher) which contains the fixes for both CVEs.
- Network Isolation: Ensure that the PaperCut management web interface (typically ports 9191 and 9192) is not accessible from the public internet. Use a VPN or Zero Trust Network Access (ZTNA) for remote administration.
- Log Analysis: Review application logs for unusual administrative logins or configuration changes originating from unexpected IP addresses.
- Endpoint Protection: Deploy EDR solutions to monitor for suspicious child processes spawned by the PaperCut service, such as cmd.exe or powershell.exe.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
