Hackers Actively Exploiting PaperCut Servers Command Execution Vulnerabilities
Brief
Two critical vulnerabilities in PaperCut servers, CVE-2026-81578 and CVE-2026-82078 , are being actively exploited, allowing attackers to execute commands, steal credentials, and potentially create privileged accounts within victim networks.
Recent reports from Arctic Wolf Threat Intelligence indicate that these vulnerabilities are being exploited to compromise networks via vulnerable PaperCut print-management servers, thereby escalating post-exploitation activities.
In a clear indication of the severity of this threat, PaperCut confirmed that active exploitation began on August 27, 2026, and that CVE identifiers were assigned the next day. By August 31, the vulnerabilities were included in CISA’s Known Exploited Vulnerabilities catalog.
