BleepingComputer reports that two PaperCut NG/MF flaws, CVE-2026-81578 and CVE-2026-82078, were patched last week after being exploited as zero-days and are now being used in data theft attacks. PaperCut issued emergency fixes for the print-management products.
The issue is not just that attackers could reach the server; it is that exploitation has already moved into theft. Once a reachable PaperCut server is compromised, the concern shifts from the bugs themselves to whatever data or access the server exposed while it was vulnerable.
For organizations running PaperCut NG or MF, the lasting question is whether the print-management server became a breach source during that window. If it did, patching closes the flaw but does not by itself undo the exposure that may already have left the server.