Published Wednesday, September 02, 2026 at 10:49 AM PT

BLUF: PaperCut NG and MF print management platforms are under active attack via a chained pair of zero-day vulnerabilities. CVE-2026-81578, a high-severity authentication bypass, combines with a second unpatched flaw to enable unauthenticated remote code execution. Immediate action required: segment PaperCut instances from untrusted networks and monitor for exploitation.
DETAILS
- Vulnerability chain: CVE-2026-81578 (authentication bypass) chains with an unidentified second zero-day to achieve pre-authentication RCE on PaperCut NG and MF print management systems.
- Affected products: PaperCut NG and MF platforms; specific version range not yet disclosed in available threat intelligence.
- Attack vector: Remote, requires no user interaction or authentication—hostile actor can execute arbitrary code directly against exposed instances.
- Active exploitation confirmed: Multiple confirmed in-the-wild attacks observed; this is not theoretical or proof-of-concept.
- CVSS and exploit details: Severity rated high; complete CVSS and technical exploit details remain preliminary pending vendor disclosure and research publication.
IMPACT
Organizations deploying PaperCut NG or MF face immediate risk of unauthorized code execution, potential lateral movement into supporting infrastructure (credential harvesting, persistence), and business disruption. Print management systems often sit on corporate networks with access to document workflows, user authentication, and sometimes financial/accounting integrations. Compromised instances can exfiltrate sensitive documents and credentials.
Exposure scope: any PaperCut NG or MF instance reachable from the internet or hostile internal network without patch is at risk.
RECOMMENDED ACTIONS
Immediate (today): Verify whether you operate PaperCut NG or MF; consult your infrastructure inventory. If yes, apply network segmentation: restrict inbound access to PaperCut to trusted administrative IPs only; move instances behind VPN or WAF if currently internet-facing.
Short-term (24–48 hrs): Monitor PaperCut access logs and process execution for anomalies. Check for unauthorized admin account creation, unexpected code execution, or failed authentication chains. Preserve logs for incident investigation.
Vendor patch: Watch for PaperCut advisory and patch availability (likely within 48–72 hrs). Test patches in pre-production immediately upon release and roll out to production as rapidly as safety permits.
Detection: Enable detection rules or threat signatures for CVE-2026-81578 in your IDS/IPS and EDR platforms once signatures are published (typically within hours to days of disclosure).
SOURCES
SOC Prime threat intelligence; initial reporting indicates coordinated zero-day research and active exploitation. Vendor statement and full technical details awaited from PaperCut official advisory.
Recent high-severity events at publish time:

