Recently patched vulnerabilities in PaperCut’s print management software are now being used in data-theft activity, according to BleepingComputer. The bugs affect PaperCut NG and PaperCut MF and are tracked as CVE-2026-81578 and CVE-2026-82078. BleepingComputer reports that the flaws were patched last week after being exploited as zero-days. PaperCut Software released two sets of emergency fixes on Thursday and Friday and published indicators of compromise intended to help defenders detect or block ongoing attacks. The technical risk is significant because the two flaws can be chained, according to BleepingComputer, to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers. That combination turns an exposed print-management server into a potential entry point for broader compromise, though the provided reporting does not establish how many real organizations have been breached. The data-theft angle comes from threat-intelligence firm Defused, which BleepingComputer says confirmed over the weekend that attackers had begun abusing the flaws in the wild. Defused said it observed PaperCut NG/MF exploit activity in honeypots since late Aug. 29 UTC and described an actor using the authentication bypass to hijack PaperCut’s external user lookup. Defused said the observed activity focused on data theft, including dumping database tables via Derby, rather than following the remote-code-execution path described in public writeups. PaperCut’s footprint makes the issue relevant beyond a narrow enterprise software niche. BleepingComputer reports, citing PaperCut Software, that PaperCut products are used by 100 million users across more than 70,000 organizations, including large companies, state agencies and educational institutions. Exposure is still hard to quantify. BleepingComputer says the Internet security watchdog Shadowserver currently tracks more than 800 PaperCut MF and NG servers exposed online, but the report notes there is no information on how many of those are honeypots or have already been secured against the attacks. The provided reporting does not attribute the current activity to a named threat actor. It also says PaperCut has not explained what attackers are doing after compromising vulnerable servers, beyond the third-party observation from Defused about database-table dumping. PaperCut has been a recurring target. BleepingComputer notes that earlier PaperCut flaws were exploited in 2023 by ransomware gangs including LockBit, Clop and Bl00dy, and that Microsoft later linked related activity to the Iranian state-backed groups Muddywater and APT35. The Cybersecurity and Infrastructure Security Agency also flagged another PaperCut remote-code-execution vulnerability, CVE-2023-2533, as actively exploited in July 2025. Who benefits: Attackers benefit from the combination of a widely deployed enterprise product and internet-exposed instances. Defenders benefit from PaperCut’s emergency patches and published indicators of compromise, if they can move quickly enough to apply and hunt against them. Who's exposed: Organizations running PaperCut NG or MF are exposed if they have vulnerable servers that remain unpatched, especially if those systems are reachable online. The provided reporting specifically notes large companies, state agencies and educational institutions among PaperCut’s customer base, but does not identify victims in the current activity.