PaperCut ships second patch as attackers hijack user lookup to dump database tables

PaperCut issued a second emergency patch for its NG and MF products as attackers pursued a data-theft path distinct from the documented remote-code-execution chain.

By · Published

Primary source: BleepingComputer

Why it matters

Attackers can repurpose PaperCut's authentication bypass for database theft, while the two disclosed flaws also provide a path to remote code execution. PaperCut has published investigation guidance and recommends rebuilding suspected servers from a clean backup.

An illustration showing data spilling from an open server rack next to a commercial printer, with a lone system administrator in the background.

PaperCut Software co-founders Chris Dance and Matt Doran started with abandoned school printouts. Attackers are now abusing an authentication bypass in their print-management software to hijack its external user-lookup function and dump database tables. BleepingComputer reported on September 1 that the activity continued after PaperCut released two emergency updates for its NG and MF products.

Dance and Doran founded PaperCut in Melbourne in 1998 after Dance, then a part-time high-school IT administrator, kept finding bins filled with abandoned printouts. The university friends wrote the first version in Dance's garage to monitor printing and reduce waste.

PaperCut's second patch is the baseline

PaperCut published its initial bulletin on August 27 and released a first emergency patch for versions 25 and 26 early on August 28 AEST. Later that day, PaperCut issued Emergency Patch Release 2 with additional hardening.

PaperCut's advisory recommends that all customers install Release 2, including those that already applied the original emergency patch. Versions 23 and earlier do not have an equivalent emergency package; those customers must upgrade to a supported release. The advisory says all versions of NG and MF are potentially affected.

Shadowserver was tracking more than 800 PaperCut NG and MF servers exposed online when BleepingComputer published its report. The count does not represent confirmed victims and can include patched systems and honeypots.

PaperCut says its software serves more than 100 million users at more than 70,000 organizations. Other counters on PaperCut's homepage display 139 million users and 89,000 organizations. The conflicting totals make the customer denominator unusable for estimating the incident's reach. No verified count of affected customers has been published.

The exploit path favors fast theft

The first vulnerability, CVE-2026-81578, is an authentication bypass that PaperCut rates 8.8 High. Under specific conditions, an unauthenticated attacker can trigger administrative backend actions before access checks finish and modify system configurations.

The second, CVE-2026-82078, is a critical unsafe class-loading vulnerability that PaperCut rates 9.4 Critical. PaperCut's database utilities could instantiate driver classes named through configuration settings without checking them against an approved list. An attacker able to alter those settings could execute arbitrary Java bytecode already available to the PaperCut server process.

BleepingComputer describes the two flaws as a chain that gives an unauthenticated attacker a route to remote code execution. Threat-intelligence provider Defused reported a different data-theft technique beginning late on August 29 UTC: an attacker abused the authentication bypass to hijack PaperCut's external user-lookup function and used the bundled Apache Derby database to dump tables.

Defused's exploitation observations on X

PaperCut has published indicators of compromise and investigation guidance for the incident. For suspected compromises, PaperCut recommends preserving backups, wiping and rebuilding the Application Server, and restoring a clean backup made before the suspicious activity.

A recurring target in overlooked infrastructure

For Dance and Doran, the incident shows the security cost of becoming embedded in routine enterprise administration. PaperCut began as a small utility for one school's discarded print jobs. The current flaws allow configuration changes, abuse of external database lookups and, when chained, remote code execution.

Attackers recognized that position years ago. In 2023, CISA and the FBI said CVE-2023-27350 allowed an unauthenticated attacker to bypass authentication and execute code remotely on affected PaperCut NG and MF installations. Microsoft linked related activity to the Clop and LockBit ransomware operations, while the CISA and FBI advisory documented attempted exploitation against education organizations by the Bl00dy ransomware gang.

On July 28, 2025, CISA added another PaperCut flaw, CVE-2023-2533, to its Known Exploited Vulnerabilities catalog.

PaperCut's response this time included two emergency releases, indicators of compromise and rebuild guidance within several days. Administrators still have to identify exposed installations and investigate the period before Release 2 was applied. Print servers rarely receive the scrutiny assigned to identity providers or internet gateways, yet PaperCut's recent history gives attackers ample reason to keep scanning for them.

Reader comments

Conversation for this story loads after sign-in.