Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Brief
Threat actors are actively exploiting two recently disclosed vulnerabilities in PaperCut NG/MF servers , using the access to execute commands, harvest credentials, conduct reconnaissance, and deploy Metasploit Meterpreter payloads.
Researchers Jens Pose and Ross Phillips observed attacks targeting PaperCut instances vulnerable to CVE-2026-81578 and CVE-2026-82078.
The activity follows PaperCut’s August 27 disclosure of active exploitation. CVE identifiers were assigned the next day, while CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31.
Hackers Exploit PaperCut NG/MF Flaws
The observed intrusion chain begins with exploitation of exposed PaperCut servers, enabling attackers to run operating-system commands through the affected application.
