Security1 distinct publisher2 min readPublished
Two flaws scoring above 8.8 in PaperCut NG and MF are under active exploitation, Huntress counts at least two victims among its own customers, and Thursday's incomplete fix means the build number is the only proof a change window worked.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The advisory does not say what the bugs are. There is no vulnerability class in the public reporting, no statement on whether CVE-2026-82078 and CVE-2026-81578 are chained or exploited separately, and no actor named for the current campaign [3]. What is public is narrow and sufficient to act on: both flaws score above 8.8, PaperCut says it has confirmed customer incidents, and more than one security firm reports exploitation in its own telemetry [1][3][6]. The 2023 round of PaperCut exploitation had names attached, Clop and Bl00dy on the criminal side [11] and an Iranian state-backed group that Microsoft said hit critical infrastructure targets with the same bug [13]. This round has none yet. That silence is more likely a gap in visibility than evidence of who is or isn't participating.
Huntress' figure sets a floor for the campaign's size. Two impacted customers is what one vendor could confirm in its own fleet [6]; it says nothing about installations with no managed detection on the print server, which is most of them.
The patch sequence is the part that changes work on the ground. The advisory went out Thursday evening with a fix that did not sufficiently address the flaws, and a corrected patch, developed with Huntress and watchTowr, landed Friday [1][2]. That is under 24 hours between a fix and its replacement [1]. Every team that ran an emergency change on Thursday and closed the ticket is still carrying the exposure [2]. The server's build number is the only proof that a change window worked; the status field in the change record is not.
Print management aggregates in a way that makes the blast radius awkward to bound. A single PaperCut instance fronts mixed fleets, Canon, Epson, Xerox and Brother among them, across universities, corporations and government [8]. watchTowr's Jake Knott put the appeal plainly: an internet-facing pivot into the corporate environment, and a treasure trove of sensitive information where printed documents are stored and can be exfiltrated [10]. Prior PaperCut bugs, he noted, were used by ransomware gangs and opportunistic attackers for initial access [9].
One detail in the advisory tells you where the exposure concentrates. PaperCut reproduced the vulnerability using information supplied by a university customer's security team [7]. Higher education found it because higher education runs it on the edge. That is the same sector CISA singled out in 2023, when it issued PaperCut guidance specifically for K-12 schools and called the education sector particularly exposed [12].
Ranked by verification strength, evidence, and original report placement.
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in PaperCut NG and PaperCut MF are under active exploitation, and released patches for the bugs, tracked as CVE-2026-82078 and CVE-2026-81578, which both carry severity scores over 8.8 out of 10.
An initial patch issued by PaperCut did not sufficiently address the vulnerabilities, and the company said it worked with experts from Huntress and watchTowr to create a new patch released on Friday.
PaperCut said: "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority."
PaperCut urged customers to remove their servers from the public internet and restrict web access to only trusted IP addresses, ensuring PaperCut server web interfaces cannot be reached from untrusted internet addresses.
PaperCut told customers: "Take this action now, even if you have not observed suspicious activity."
Multiple cybersecurity companies confirmed evidence of exploitation, including Huntress, which said it has at least two customers impacted by the campaign targeting the bugs.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
security
SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-anchored, thinly corroborated
Nearly everything load-carrying — the CVE pair, the above-8.8 scores, the admission that the first fix missed — comes from PaperCut's own advisory as relayed by The Record. The outside checks are two: Huntress counting affected customers in its own telemetry, and watchTowr putting its name on the corrected patch. Against that, there is no exposure scan, no indicator, no bug class, and no fixed build number, which is precisely the evidence a defender would use to confirm the story applies to them.
Exploitation real, blast radius uncounted
Two things are concretely happening in the world: attackers are landing on PaperCut servers, and the vendor has shipped fixes twice inside a day. Both are documented events, not projections. But the measurable footprint stops at Huntress's 'at least two' customers — PaperCut's reach across universities, corporations and governments is described qualitatively and nobody quantifies exposed servers or how many sites have taken either patch.
Urgency language outruns the counted damage
The severity framing — 'highest priority', scores above 8.8, act now regardless of what you see — sits some distance ahead of the only tally anyone offers, which is two customers at one security vendor. The gap is small rather than serious, because the two facts doing the most work in the story are not promotional: a company saying its own patch failed, and researchers whose product telemetry shows hits. PaperCut's 2023 history of ransomware and state-backed abuse also makes pre-emptive alarm the defensible posture.
A vendor confessing, two IR firms getting credited
Read the sourcing for who gains. Huntress and watchTowr are named as the outside experts who fixed what PaperCut could not, and Huntress is also the sole supplier of the victim count — visibility that happens to advertise exactly what those firms sell. PaperCut pulls the other way: admitting a bad patch and telling customers to yank servets off the internet costs it something, which is why the timeline reads as credible. A university customer's security team, meanwhile, is the one contributor here with nothing to sell.
Checkable specifics, single account
The story hands over things that can be falsified within days — two CVE identifiers, a two-patch sequence, a named collaborator on the second fix — and that keeps confidence respectable despite one publisher carrying it. What holds the number down is the unanswered middle: no bug class, no actor, no fixed version, so an operator cannot yet confirm from the reporting alone whether their environment is clean.