Security1 distinct publisher2 min readPublished
PaperCut shipped emergency fixes for CVE-2026-81578 and CVE-2026-82078 on Thursday and Friday, and by the weekend Defused was watching honeypot intruders bypass authentication and read database tables instead of running code.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The step that decides how you hunt is the second one. Defused says the actor uses the authentication bypass to hijack PaperCut's external user-lookup and pull database tables out through Derby, which is not the remote code execution route shown in the public writeups [6]. Nothing spawns. A print server that never runs an unexpected child process can still be handing over its database, and detection content built against the RCE proof of concept is watching for the wrong artifact [16]. PaperCut shipped indicators of compromise alongside the fixes [3], but the vendor has not described what the intruders do after access [4], so whether those indicators cover the query path is something defenders have to check for themselves.
Scope, with the arithmetic shown. Shadowserver counts more than 800 PaperCut MF and NG servers reachable from the internet [8]. PaperCut says the software runs at more than 70,000 organizations and 100 million users [7]. That works out to roughly 1.1 percent [14], and it is the wrong denominator for risk. The 800 are the servers an attacker can reach with no foothold; the rest sit inside, where a pre-auth chain works as a lateral tool once someone is already on the network. Shadowserver's figure also includes honeypots and hosts that may already be patched [8].
The gap between fix and exploitation was short. The two emergency patch sets landed Thursday and Friday [3]. Defused recorded honeypot activity from late on August 29 UTC [5], about a day after the second set [15].
This is well-worn ground for the product. The April 2023 chain of CVE-2023-27350 and CVE-2023-27351 was tied to LockBit and Clop [9]. Microsoft reported two weeks later that MuddyWater and APT35 had joined in [10]. The FBI and CISA warned in May 2023 that the Bl00dy gang was using the same RCE bug for initial access [12], and CISA flagged CVE-2023-2533 as actively exploited in July 2025 [13]. Counting the current pair, that is three separate PaperCut bug sets exploited in the wild since 2023 [17].
What the 2023 crews wanted was Print Archiving, the feature that keeps a copy of every document sent through the server [11]. The draw has not changed much. A print server is a document store with a queue attached, and per Defused, the current activity is reading it [6].
Ranked by verification strength, evidence, and original report placement.
CVE-2026-81578 and CVE-2026-82078 are two flaws in PaperCut NG and MF print management software that can be chained to bypass authentication and gain remote code execution on vulnerable servers.
The two vulnerabilities were patched last week after being exploited as zero-days, and are now being abused in data theft attacks.
PaperCut Software released two sets of emergency patches on Thursday and Friday and published indicators of compromise to help defenders block ongoing attacks.
PaperCut Software has not attributed the attacks or explained what the threat actors are doing after compromising vulnerable servers.
Threat intelligence company Defused said it has observed CVE-2026-81578 / CVE-2026-82078 exploit activity in its honeypots since late on August 29 UTC.
Defused said an actor is abusing the auth bypass to hijack PaperCut's external user-lookup and that, unlike the RCE path in public writeups, the actor goes for data theft by dumping database tables via Derby.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
build
An unwhitelisted JDBC driver name turns PaperCut's management port into SYSTEM1 distinct publisher
security
SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Three named upstream voices, one outlet carrying them
The load of this story is spread across a vendor that patched and published indicators, a threat-intelligence firm quoting its own honeypots, and a scanning project counting exposed hosts — all reaching us through BleepingComputer alone. That is decent sourcing and no corroboration: nobody has independently seen the Derby table dumps, no victim is named, and the vendor explicitly declines to describe what happens after a compromise. The 2023 and 2025 history is the firmest material here, because CISA, the FBI and Microsoft put it on the record at the time.
Attacker uptake confirmed, defender uptake unknown
What is measurably happening: fixes are out, indicators are published, and at least one actor was working the chain within about a day of the second patch. What is not measured is the other half of adoption — of the 800-plus servers Shadowserver can see, we are told nothing about how many are patched, and those 800 sit against a claimed 70,000-organization base, so the visible surface is roughly one percent of the estate. Exploitation is real and narrow in observation; remediation progress is simply dark.
A tweet-length telemetry note carrying a headline
"Used in data theft attacks" is doing more work than its evidence. The theft is a honeypot observation from a single firm, described in two sentences; honeypot hits prove an actor is trying the technique, not that customer databases have walked out the door. Against that, the story understates one thing genuinely worth alarm — detection written from the public code-execution writeups will look straight past a chain that ends in database reads. Overstated headline, underplayed defensive gap.
Silence from the vendor, visibility for the sensor
Every party here is positioned. PaperCut controls the patch narrative and benefits from saying nothing about attribution or impact while customers are still exposed. Defused sells threat intelligence, and a first-to-see honeypot finding is the product demonstrating itself. Its own numbers — 100 million users, 70,000 organizations — are marketing figures being repurposed as risk scope, and the story closes with a promotional pitch for a security vendor's report, which tells you something about the economics of the page.
Sturdy on sequence, thin on consequence
We would stand behind the timeline, the identifiers, the fact of the emergency fixes and the exploitation history without hesitation — those are checkable and consistent. Confidence falls off sharply on the part readers care about most: who is doing this, how many organizations lost data, and whether the observed Derby path is the main one or a curiosity from one sensor. One publisher, one sensor operator, no victims on the record.