Hackers Target PaperCut Print Management Software with Command‑Execution Flaws
Security researchers have confirmed that two newly disclosed flaws in PaperCut print‑management servers are being leveraged in the wild, giving adversaries the ability to run arbitrary code, harvest credentials and, in some cases, establish privileged accounts inside corporate networks.
The vulnerabilities, catalogued as CVE‑2026‑81578 and CVE‑2026‑82078, reside in the server's web interface and authentication modules. Exploitation permits attackers to inject system commands that execute with the same privileges as the PaperCut service, effectively turning the print server into a foothold for lateral movement.
PaperCut is deployed in thousands of schools, universities, hospitals and enterprises to centralise printing, track usage and enforce policies. Because the software often runs on internal Windows or Linux servers with broad network access, compromising it can provide a conduit to other critical systems, making the flaws especially valuable to threat actors seeking stealthy persistence.
Threat‑intelligence firm Arctic Wolf reported seeing active exploitation attempts within days of the vulnerabilities' public disclosure. Their sensors captured malicious requests targeting the vulnerable endpoints, and in several instances the payloads succeeded in retrieving service‑account passwords stored on the server. The firm warned that the activity appears to be coordinated and that attackers are likely scanning for unpatched installations globally.
PaperCut has issued security advisories urging administrators to apply the vendor‑released patches immediately and to enforce network segmentation for print servers. Experts also recommend disabling unnecessary web‑based features, rotating service credentials, and monitoring for anomalous command‑execution patterns in system logs.
As organizations continue to modernise their IT environments, the incident underscores the broader risk posed by legacy infrastructure components that remain exposed to the internet or internal threats. Prompt remediation, combined with regular vulnerability assessments, will be essential to prevent these command‑execution bugs from being used as stepping stones for larger breaches.
Comments (0)
Be the first to comment.
Join the discussion