Security Leaders Weigh in on Recent PaperCut Vulnerabilities
.webp?t=1788184130)
On August 27, PaperCut announced that hackers were exploiting a vulnerability to access sensitive information. PaperCut has shared CVE identifiers for the two vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578.
Security leaders have shared their thoughts on the recent news below:
Jacob Warner, Director of IT, Xcape, Inc:
"Boring infrastructure with credential-free remote code execution and self-erasing payloads is how a print server becomes a domain-wide incident. When an unauthenticated request becomes SYSTEM on your print server, the resulting administrative compromise transforms routine utility services into elevated beachheads for lateral movement across enterprise environments. Because the attacker cleans up after themselves, security teams must patch now and assume the logs will not tell them if they were late to respond. Traditional vulnerability scanners often miss active zero-day exploitation until vendor signatures catch up. Defenders should patch or isolate today, close all Internet exposure, and image affected machines before remediation, as the attacker's cleanup routine may have already deleted the logs that would have confirmed exposure.
Unauthenticated remote code execution on print management software grants immediate elevated privileges, escalating utility software into a full domain threat. Self-erasing payloads and automated log deletion mean security teams cannot rely solely on post-incident forensic artifacts to detect compromise. Immediate containment requires closing all Internet exposure, imaging affected application servers prior to remediation, and applying vendor patches immediately. Boring utility servers make the best targets because nobody expects the print spooler to hand over domain administrator rights."
Seemant Sehgal, Founder & CEO, BreachLock:
"Pre-authentication RCE means the attacker needs nothing from you. No credentials, no foothold, no prior access, before they own the application and can run arbitrary Java on your infrastructure. The first question every team should be answering right now is whether their PaperCut instance is reachable from the internet, because if it is, that answer is more urgent than any patch timeline. Vulnerability scanners will tell you the CVE exists, but they will not tell you whether an attacker already walked through it and what the impact would be if they did."
Denis Calderon, Principal & CTO, Suzu Labs:
"PaperCut's Application Server runs as SYSTEM on Windows, manages configurations for every endpoint in the org, and has a web-accessible console that is often exposed to the Internet. It's “just printing”, but in this case, its important to treat it like any other management plane that holds implicit trust within your network.
I ran a Shodan query this morning and found over 1,000 of these servers exposed to the public internet on their default management ports. A lot of them look like schools. That makes sense. PaperCut is heavily deployed in education for managing student print quotas, and students need to access the system from their own devices, so the web interface ends up internet-facing almost by necessity. The first confirmed victim to report this exploitation to PaperCut was a university. These servers are findable in seconds, they require zero credentials to exploit, and the attacker gets SYSTEM-level code execution. Unfortunately, even a well managed vulnerability scanning program wouldn't have flagged this since it was a zero-day, and you can’t see vulnerabilities that haven't been discovered yet. That's the fundamental limitation. The exposure itself was the risk, long before anyone knew the specific flaw."
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





.webp?height=200&t=1785249752&width=200)

