VulnerabilityBleeping Computer
9.8 — CRITICAL
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Two previously patched zero-day vulnerabilities in PaperCut NG and MF print management software are being exploited in data theft attacks, targeting over 100 million users across more than 70,000 organizations.
⚙️Technical Details
CVEs
CVE-2026-81578CVE-2026-82078
Affected Systems
Papercut Papercut MfPapercut Papercut Ng
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Over 100 million users across more than 70,000 organizations
🛡️Recommended Actions
1Apply the latest patches for CVE-2026-81578 and CVE-2026-82078 as soon as possible
2Enable authentication and authorization mechanisms to prevent unauthorized access
3Monitor system logs and network traffic for suspicious activity related to PaperCut NG and MF
📦Affected Products
Papercut Papercut MfPapercut Papercut Ng
🔐NVD Verified DataVERIFIED
CVE-2026-81578 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-305
Affected Products (CPE)
Papercut Papercut MfPapercut Papercut Ng
CVE-2026-82078 ↗CVSS 9.1 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-470
Affected Products (CPE)
Papercut Papercut MfPapercut Papercut Ng
CVE-2023-2533 ↗CVSS 8.8 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWeaknesses
CWE-352
Affected Products (CPE)
Papercut Papercut MfPapercut Papercut Ng
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
