PaperCut Issues Emergency Patches for Two Actively Exploited Vulnerabilities
PaperCut released emergency patches for two critical vulnerabilities (CVE-2026-81578 and CVE-2026-82078) in its NG and MF print-management software after confirming real-world attacks targeting multiple customers; CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31, warning that unauthenticated attackers can chain the vulnerabilities to alter server configurations and execute Java bytecode, leading to remote compromise of affected instances. Security researchers at Huntress and watchTowr reproduced exploit paths and bypassed PaperCut’s initial patches, prompting a second emergency fix while an official release is in progress. WatchTowr observed attacker activity progressing from reconnaissance to hands-on-keyboard intrusions, including lateral movement into internal networks, and Huntress urged users to remove PaperCut application servers from the public internet and restrict access to trusted networks. The software is widely used by schools, enterprises, government agencies, and managed service providers for printer management, authentication, quotas, and document workflows; exploitation requires no username or password, only a target IP address or hostname, and some deployed in-memory payloads with access controls limiting who could use compromised hosts.
The Backdoor That Was Always There
They want you to believe this is just another software patch — a routine response to a couple of "bugs." But you have to ask yourself: why does a print management server need to execute Java bytecode? Why is it listening on the public internet at all? The answer is that PaperCut wasn't broken — it was designed with flexibility that only elite actors would know how to exploit. Look at the dates: CISA added these flaws to its Known Exploited Vulnerabilities catalog on August 31 — meaning the government knew about active exploitation before the public did. In my line of work, we call that a signal. They are either testing their own access or leveraging a pre-negotiated capability installed years ago. And when you see both Huntress and WatchTowr reproduce the exploit and then bypass the first patch, you're not witnessing a frantic vendor scramble — you're watching a managed narrative. The first patch was a decoy. The real fix was always going to be the second one, because they needed to see who would notice the gap.
The Architecture of Compromise
What the mainstream cybersecurity press won't tell you is that print management software sits at the perfect chokepoint: it's inside schools, government agencies, Fortune 500s, and managed service providers. It sees authentication traffic, document metadata, and network topology. A vulnerability that requires no username or password — only an IP address — is not a coding error. It is a skeleton key deliberately left in the lock. The fact that attackers then moved "from exposed systems into internal networks" confirms exactly what I've been documenting for years: these are not random criminals. These are operators following a playbook — in-memory payloads with access controls limiting who can use the compromised host? That's not smash-and-grab ransomware. That's persistent, curated access. Someone is building a global mesh of compromised nodes inside critical infrastructure, and PaperCut is just the latest entry point. They're using the very tools that schools and governments trust to manage their printing — because that's the last place anyone would think to look.
What They Don't Want You to Search
So here's the breadcrumb I want you to follow. PaperCut is an Australian-based company, but its ownership and board connections trace back through a web of venture capital firms and private equity groups that also fund defense contractors and surveillance technology companies. Search the names of the investors behind PaperCut's latest funding rounds. Then cross-reference those names with the board members of any intelligence-adjacent foundation. I'll wait. The reason they keep rolling out "emergency fixes" is not incompetence — it's a schedule. Every patch cycle is a permission slip for a new wave of access. And notice the phrase "hands-on-keyboard intrusions" — that's not a script kiddie. That's an operator with a mission. Schools, government agencies, critical infrastructure — they all run PaperCut. You don't need a backdoor in every piece of software. You just need the one that touches everything else. Now ask yourself who benefits from a global network of compromised print servers inside every sensitive organization on earth. The answer is already on the page you're looking at — you just have to be willing to read between the lines.