Home » PaperCut Zero-Day Exploitation Escalates to Active Intrusions
Enterprise print management systems are often treated as routine infrastructure, but attackers continue to demonstrate that any connected application can become an entry point into a corporate environment.
According to SecurityWeek report, threat actors are actively exploiting two recently disclosed vulnerabilities in PaperCut NG/MF, with attacks now escalating from reconnaissance to hands-on-keyboard activity. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, can allow unauthenticated attackers to bypass authentication and achieve remote code execution on affected systems.
PaperCut has released emergency patches and additional hardening after researchers identified further bypass concerns. SecurityWeek also reported that roughly 1,000 PaperCut instances are currently exposed to the internet.
The exploitation begins when attackers identify a vulnerable PaperCut NG/MF deployment.
One of the vulnerabilities, CVE-2026-81578, is an authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations. The second vulnerability, CVE-2026-82078, involves unsafe dynamic class loading and can ultimately enable arbitrary Java bytecode execution within the PaperCut server process.
This combination turns a vulnerable print management server into a potential foothold inside an organisation.
Unlike attacks that require stolen credentials, the PaperCut vulnerabilities can be exploited without legitimate authentication.
Once the authentication controls are bypassed, attackers can manipulate system configuration and move toward executing malicious code on the affected server.
This makes the attack particularly concerning for organisations where PaperCut infrastructure has access to internal networks or other enterprise resources.
Successful exploitation can give attackers control over the execution environment of the PaperCut server.
From there, attackers may attempt to:
Security researchers monitoring the campaign have observed system discovery activity, demonstrating that exploitation can progress beyond simply gaining initial access.
The PaperCut incident highlights several risks that security teams need to consider.
First, the vulnerabilities are being actively exploited.
Second, exploitation does not require legitimate authentication.
Third, a compromised application server can become a starting point for activity elsewhere in the environment.
Finally, attackers may already have interacted with vulnerable systems before organisations apply the available patches.
This means patching is critical, but organisations also need to determine whether exploitation occurred before remediation.
Security teams should investigate:
Organisations should also review historical activity around vulnerable instances rather than assuming that applying the latest patch eliminates the possibility of prior compromise.
PaperCut users should identify affected NG/MF deployments and apply the latest emergency patches and vendor-recommended mitigations.
Organisations should also:
SecurityWeek reported that PaperCut has provided indicators of compromise and that additional emergency hardening was required after further bypass concerns were identified.
This attack is primarily an application exploitation, authentication bypass, remote code execution, network activity, and potential lateral movement problem.
The most relevant Seceon capabilities are aiSecurityScore360, aiSIEM / CGuard, and aiXDR-PMax.
Seceon’s aiSecurityScore360 can help organisations understand their external attack surface and identify assets that require remediation priority.
For a vulnerability such as the PaperCut zero-days, this visibility can help security teams identify:
This helps move vulnerability management beyond simply knowing that a vulnerability exists to understanding where the organisation is actually exposed.
Seceon’s aiSIEM / CGuard can provide cross-environment correlation around a potentially compromised PaperCut server.
It can help security teams correlate:
For example, an authentication anomaly followed by unexpected PaperCut server activity and suspicious outbound communication becomes much more meaningful when those events are correlated as part of a single attack chain.
This type of correlation can help the SOC distinguish routine application activity from behaviour associated with an active intrusion.
Once exploitation results in activity on the affected server or connected endpoints, aiXDR-PMax can provide behavioural visibility into what happens next.
It can help security teams identify:
This is particularly important when attackers move from vulnerability exploitation to hands-on activity.
The goal is not simply to detect that a vulnerable PaperCut server exists, but to identify what an attacker is doing after gaining access.
The PaperCut zero-day campaign demonstrates why vulnerability management and threat detection cannot operate independently.
A patch can close an exploited vulnerability, but it cannot tell an organisation whether attackers already accessed the system or what they did after gaining entry.
The key defensive lesson is clear.
Security teams need visibility from exposure to exploitation and from exploitation to post-compromise activity.
With aiSecurityScore360, aiSIEM / CGuard, and aiXDR-PMax, Seceon can help organisations identify exposed infrastructure, correlate suspicious activity, detect behavioural indicators, and accelerate investigation and response.
The question is no longer simply:
“Have we patched the vulnerable system?”
It is:
“Did anyone exploit it, and what happened after they got in?”
Copyright @Seceon Inc 2026. All Rights Reserved.