Chained PaperCut vulnerabilities let hackers take over print servers without a password
Two flaws in PaperCut NG and MF print management software can be chained for full unauthenticated server takeover using only a target's IP address. CISA added both to its exploited vulnerabilities list; hundreds of servers remain exposed.
Security researchers say two chained vulnerabilities in PaperCut NG and MF, CVE-2026-81578 and CVE-2026-82078, let an attacker take full control of a print server with no username or password, needing only its IP address or hostname. Huntress detected the first attack activity on August 26, 2026, and an education-sector customer reported a suspected breach the next day. Rapid7 says compromised organizations have seen attackers bring their own remote-management tools to maintain access. CISA added both flaws to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 11 and 14 to patch. Shadowserver counted over 200 vulnerable servers still exposed this week, about 60 of them in the US, with additional cases in Denmark and Ireland. PaperCut has released a third emergency patch. The company faced a similarly serious vulnerability in 2023, underscoring how deeply print management software sits inside institutional networks tied to identity and directory systems.