bleeping-computer · Crawled Sep 1, 2026
Recently patched PaperCut zero-days used in data theft attacks
Read original article ↗AI Summary
Two recently patched zero-day vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078, are being actively exploited in data theft attacks. Attackers are chaining the flaws to bypass authentication and access backend databases via PaperCut's external user-lookup functionality, using the vulnerabilities to dump database tables through Derby without executing remote code. Threat intelligence firm Defused observed the exploit activity in honeypots starting August 29, 2026, indicating ongoing abuse by unidentified actors.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.