PaperCut Zero-Day Exploitation Escalates to Active Intrusions

PaperCut Zero-Day Exploitation Escalates to Active Intrusions

Enterprise print management systems are often treated as routine infrastructure, but attackers continue to demonstrate that any connected application can become an entry point into a corporate environment.

According to SecurityWeek report, threat actors are actively exploiting two recently disclosed vulnerabilities in PaperCut NG/MF, with attacks now escalating from reconnaissance to hands-on-keyboard activity. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, can allow unauthenticated attackers to bypass authentication and achieve remote code execution on affected systems.

PaperCut has released emergency patches and additional hardening after researchers identified further bypass concerns. SecurityWeek also reported that roughly 1,000 PaperCut instances are currently exposed to the internet.

The Attack Starts With an Exposed PaperCut Instance

The exploitation begins when attackers identify a vulnerable PaperCut NG/MF deployment.

One of the vulnerabilities, CVE-2026-81578, is an authentication bypass that allows a remote, unauthenticated attacker to modify certain system configurations. The second vulnerability, CVE-2026-82078, involves unsafe dynamic class loading and can ultimately enable arbitrary Java bytecode execution within the PaperCut server process.

This combination turns a vulnerable print management server into a potential foothold inside an organisation.

Authentication Bypass Opens the Door

Unlike attacks that require stolen credentials, the PaperCut vulnerabilities can be exploited without legitimate authentication.

Once the authentication controls are bypassed, attackers can manipulate system configuration and move toward executing malicious code on the affected server.

This makes the attack particularly concerning for organisations where PaperCut infrastructure has access to internal networks or other enterprise resources.

Remote Code Execution Enables Further Activity

Successful exploitation can give attackers control over the execution environment of the PaperCut server.

From there, attackers may attempt to:

  • Discover internal systems
  • Identify users and privileged accounts
  • Search for credentials
  • Establish persistence
  • Move laterally
  • Access sensitive information
  • Deploy additional malware
  • Prepare for ransomware or other disruptive activity

Security researchers monitoring the campaign have observed system discovery activity, demonstrating that exploitation can progress beyond simply gaining initial access.

Why This Attack Is Particularly Dangerous

The PaperCut incident highlights several risks that security teams need to consider.

First, the vulnerabilities are being actively exploited.

Second, exploitation does not require legitimate authentication.

Third, a compromised application server can become a starting point for activity elsewhere in the environment.

Finally, attackers may already have interacted with vulnerable systems before organisations apply the available patches.

This means patching is critical, but organisations also need to determine whether exploitation occurred before remediation.

What Organizations Should Look For

Security teams should investigate:

  • Internet-facing PaperCut NG/MF instances
  • Unexpected authentication or configuration changes
  • Suspicious activity involving the PaperCut application server
  • Unexpected process execution
  • Unusual outbound network connections
  • Changes to server configuration
  • Suspicious administrative activity
  • Internal reconnaissance originating from the PaperCut server
  • Lateral movement attempts
  • Indicators of persistence or additional malware

Organisations should also review historical activity around vulnerable instances rather than assuming that applying the latest patch eliminates the possibility of prior compromise.

What Organizations Should Do

PaperCut users should identify affected NG/MF deployments and apply the latest emergency patches and vendor-recommended mitigations.

Organisations should also:

  • Restrict unnecessary internet exposure
  • Limit access to trusted networks or sources
  • Review PaperCut server logs and security telemetry
  • Investigate suspicious activity before and after patching
  • Monitor for unusual process and network behaviour
  • Segment application infrastructure where possible
  • Review privileged-account activity
  • Hunt for signs of lateral movement

SecurityWeek reported that PaperCut has provided indicators of compromise and that additional emergency hardening was required after further bypass concerns were identified.

How Seceon Helps Defend Against PaperCut Exploitation

This attack is primarily an application exploitation, authentication bypass, remote code execution, network activity, and potential lateral movement problem.

The most relevant Seceon capabilities are aiSecurityScore360, aiSIEM / CGuard, and aiXDR-PMax.

aiSecurityScore360

Seceon’s aiSecurityScore360 can help organisations understand their external attack surface and identify assets that require remediation priority.

For a vulnerability such as the PaperCut zero-days, this visibility can help security teams identify:

  • Internet-facing assets
  • Exposed PaperCut infrastructure
  • Vulnerability exposure
  • Assets requiring immediate remediation
  • Security posture gaps

This helps move vulnerability management beyond simply knowing that a vulnerability exists to understanding where the organisation is actually exposed.

aiSIEM / CGuard

Seceon’s aiSIEM / CGuard can provide cross-environment correlation around a potentially compromised PaperCut server.

It can help security teams correlate:

  • Authentication events
  • Application activity
  • Configuration changes
  • Endpoint events
  • Network connections
  • Administrative activity
  • Internal reconnaissance
  • Lateral movement indicators

For example, an authentication anomaly followed by unexpected PaperCut server activity and suspicious outbound communication becomes much more meaningful when those events are correlated as part of a single attack chain.

This type of correlation can help the SOC distinguish routine application activity from behaviour associated with an active intrusion.

aiXDR-PMax

Once exploitation results in activity on the affected server or connected endpoints, aiXDR-PMax can provide behavioural visibility into what happens next.

It can help security teams identify:

  • Suspicious process execution
  • Unexpected command activity
  • Abnormal system behaviour
  • Persistence attempts
  • Lateral movement
  • Suspicious network communication
  • Post-exploitation activity

This is particularly important when attackers move from vulnerability exploitation to hands-on activity.

The goal is not simply to detect that a vulnerable PaperCut server exists, but to identify what an attacker is doing after gaining access.

Final Thoughts

The PaperCut zero-day campaign demonstrates why vulnerability management and threat detection cannot operate independently.

A patch can close an exploited vulnerability, but it cannot tell an organisation whether attackers already accessed the system or what they did after gaining entry.

The key defensive lesson is clear.

Security teams need visibility from exposure to exploitation and from exploitation to post-compromise activity.

With aiSecurityScore360, aiSIEM / CGuard, and aiXDR-PMax, Seceon can help organisations identify exposed infrastructure, correlate suspicious activity, detect behavioural indicators, and accelerate investigation and response.

The question is no longer simply:

“Have we patched the vulnerable system?”

It is:

“Did anyone exploit it, and what happened after they got in?”

Categories

Seceon Inc