Skip to main content
Home/Blog/The Software Running Your Office Printers Just Got Hacked. Here's Why That's a Bigger Problem Than You Think.
Cybersecurity

The Software Running Your Office Printers Just Got Hacked. Here's Why That's a Bigger Problem Than You Think.

PaperCut print management software is being actively exploited via two zero-day vulnerabilities. With 47% of tracked installations still unpatched, here's what every business leader needs to know.

August 31, 2026·7 min read

Most business leaders don't spend much time thinking about their print management software. It handles print queues, tracks usage, manages access to copiers and printers — foundational but unglamorous infrastructure that hums along invisibly in the background.

That invisibility is exactly the problem.

On August 27, 2026, PaperCut Software issued an urgent security advisory: its NG and MF print management products were being actively exploited by attackers. Two zero-day vulnerabilities — CVE-2026-81578 and CVE-2026-82078 — had been chained together to give unauthenticated attackers full remote code execution on affected servers. No username. No password. Just network access and control of your print server.

As of this writing, 47% of tracked PaperCut installations are still running unpatched versions. Half.

What Happened — In Plain English

PaperCut NG and MF are print and device management platforms used by tens of thousands of organizations worldwide — schools, hospitals, law firms, manufacturers, government agencies. If your organization manages a fleet of printers across multiple departments or locations, there's a real chance PaperCut is the software running behind it.

The first vulnerability (CVE-2026-81578) is an authentication bypass in PaperCut's web management interface. An attacker who can reach that interface over a network doesn't need credentials — they can modify system configurations directly. Think of it as walking through a locked door that turns out not to be locked.

The second vulnerability (CVE-2026-82078) is a class-loading flaw in PaperCut's database connection utilities. Once an attacker has manipulated system configurations, they can trigger arbitrary Java code execution on the server. The two flaws chain together: the first opens the door, the second lets the attacker take full control of the room.

Huntress, the security firm that discovered and reported the vulnerabilities, confirmed active exploitation in customer environments beginning August 26. Observed post-exploitation activity included system discovery commands — attackers mapping what they had access to, almost certainly in preparation for the next phase.

PaperCut released an emergency patch, then a second emergency patch when watchTowr Labs discovered additional bypasses in the first fix. As of today, the investigation is still active.

Why Print Management Software Is a Target Worth Understanding

Here's the business logic that attackers understand, even if most organizations don't: print management servers often sit in a privileged position on the corporate network. They communicate with workstations, servers, and network devices across the organization. They frequently hold credentials for connecting to those systems. And because they're treated as infrastructure — not business applications — they tend to be under-monitored and under-patched.

This is the same pattern we've seen repeatedly across enterprise software over the past year: the attack surface isn't always where your attention is.

Your SOC is watching for suspicious logins and endpoint alerts. Your security team has policies around Microsoft 365 and your ERP system. But the print server? The backup management console? The network monitoring appliance? Those systems sit in the gap between IT infrastructure and active security monitoring — and attackers know it.

Huntress noted that 47% of the approximately 2,500 PaperCut installations they track are running version 23 or older — software for which no emergency patch currently exists. Organizations on those versions have only one near-term option: network isolation.

The Patch Lag Problem Is Getting Worse

The 47% unpatched figure isn't a PaperCut-specific failure. It reflects something systemic about how organizations manage software they consider infrastructure.

When a critical vulnerability hits your primary business applications — your CRM, your ERP, your Microsoft 365 tenant — there's usually a clear owner, a defined patching process, and some accountability for getting it done. Infrastructure software like print management tools, backup systems, and network appliances often lacks that clarity.

Who owns patching the PaperCut server in your environment? Is it IT? The managed service provider? The vendor? In many organizations, the honest answer is: no one has explicitly thought about it.

That ownership gap is what turns a software vulnerability into a breach. The vulnerability is the risk. The gap in accountability is what converts it to an incident.

Three Questions Every Business Leader Should Ask Today

You don't need to become a PaperCut expert. But you do need to close the visibility gap on infrastructure software in your environment.

First: Do we use PaperCut, and if so, what version? This seems like a question your IT team should be able to answer in five minutes. If it takes longer than that — or if the answer is uncertain — you have a software inventory problem that extends well beyond print management.

Second: Who explicitly owns patching our infrastructure software? Not just endpoints and servers, but the management layer — print servers, backup systems, monitoring tools, network appliances. If there isn't a clear owner with a defined process, you have an accountability gap. Patch ownership needs to be assigned, documented, and verified.

Third: Are our management interfaces exposed to the internet? PaperCut's own advisory urges organizations to immediately restrict web access to their Application Server to trusted IP addresses only. Management interfaces for infrastructure tools should virtually never be reachable from the public internet. If yours are, that's a configuration issue that predates this vulnerability — and it's worth fixing regardless.

The Pattern Worth Recognizing

PaperCut is in the news today. Tomorrow it will be something else — a backup appliance, a network monitoring tool, a firmware update system. The category changes. The pattern doesn't.

Attackers have become very good at identifying software that large numbers of organizations run, that organizations treat as invisible infrastructure, that sits in privileged network positions, and that tends to get patched last. That's the playbook.

The defensive answer isn't to become expert in every piece of software that might be in your environment. It's to build organizational discipline around three things: knowing what software you're running, knowing who owns keeping it current, and ensuring management interfaces are appropriately restricted.

The PaperCut zero-day will be patched. The underlying conditions that made it dangerous — the invisibility, the lack of ownership, the exposure — will persist until someone explicitly addresses them.

What TrustPoint Cyber Does

We help organizations build the visibility and accountability structures that make these incidents containable rather than catastrophic. If you're uncertain about your software inventory, your patch ownership model, or your exposure to management interface risks, let's talk. The conversation is straightforward. The exposure is worth closing.

Get Protected

Ready to strengthen your security?

TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.