$ techbeacon▋
CVE & Exploits

Hackers Target PaperCut Print Management Software Exploiting New CVEs

Hackers Target PaperCut Print Management Software Exploiting New CVEs

Security researchers have confirmed that malicious actors are actively exploiting two newly disclosed vulnerabilities in PaperCut NG and MF print management solutions, identified as CVE-2026-81578 and CVE-2026-82078. The flaws enable attackers to gain unauthorized control over print servers, extract stored credentials, and execute Meterpreter payloads, raising concerns for enterprises that rely on the software for document handling.

The vulnerabilities stem from improper input validation and insecure handling of authentication tokens within the PaperCut web interface. Exploitation of CVE-2026-81578 permits remote code execution by injecting malicious commands, while CVE-2026-82078 allows privilege escalation that can be used to harvest administrative credentials stored on the server. Together, the chain of exploits gives threat actors a foothold to move laterally across corporate networks.

PaperCut, a popular print management platform used by schools, government agencies, and large corporations, has long been praised for its cost‑saving features and centralized control. However, the recent attacks highlight the broader risk that seemingly peripheral IT systems pose when compromised. Print servers often have access to internal directories and can act as a bridge between isolated network segments, making them attractive targets for attackers seeking to expand their reach.

Industry observers note that the use of Meterpreter—a flexible payload commonly employed by the Metasploit framework—suggests that the attackers are leveraging well‑known penetration‑testing tools for malicious purposes. This approach enables rapid deployment of additional modules, such as data exfiltration utilities or ransomware droppers, once the initial foothold is secured. The active exploitation reported by GBHackers indicates that threat groups are already weaponizing the flaws in the wild, underscoring the urgency for organizations to patch their environments.

PaperCut has issued an advisory urging customers to apply the latest security updates, which address both CVEs and incorporate additional hardening measures. Administrators are also advised to review access controls, enforce multi‑factor authentication for privileged accounts, and monitor network traffic for anomalous activity originating from print servers. Cyber‑security firms recommend immediate network segmentation of print infrastructure and the deployment of intrusion‑detection systems to flag suspicious payload execution.

Experts anticipate that the disclosure may spur a wave of scanning activity as attackers search for vulnerable installations. While no large‑scale data breach linked directly to these exploits has been publicly confirmed, the potential for credential theft and subsequent network compromise remains significant. Organizations that have not yet upgraded their PaperCut installations should prioritize remediation to mitigate the risk of further intrusion.

Source: GBHackers
Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related