Back to The Local Vocal
The Local VocalHigh
Email
High risk 3rd Party Advisory 17 September 2026
RegionNew Zealand

Patch PaperCut before someone gets in

Attackers are already exploiting newly disclosed PaperCut flaws to break into education environments and steal credentials, so if you run PaperCut you need to patch and review access now.

This is not a phishing email, it is a live software advisory about PaperCut print management servers. Security researchers observed attackers exploiting two newly disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in a chain that bypasses authentication and enables remote code execution. The activity has been seen against schools and universities overseas, but the exposure matters to any NZ organisation running PaperCut.

What gives this urgency is that the flaws are already being actively utilised, not just theoretically described. In plain terms, an attacker can get past the normal sign-in checks on an exposed PaperCut server, run their own commands, and quietly look around the system. That means a vulnerable server can become an entry point even if your staff have done nothing wrong.

The likely goal is credential theft and deeper access into your environment. If attackers can execute commands and perform reconnaissance on a PaperCut server, they may be able to harvest usernames and passwords, move further into your network, and use trusted systems to widen the compromise. If you rely on PaperCut anywhere in your business, you should treat this as a patch now and investigate now issue.

Source: The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html

Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Confirm whether PaperCut is present anywhere in your environment, including print servers managed by internal IT or a third-party provider.
  • Check: Review your PaperCut version, apply the vendor fixes for CVE-2026-81578 and CVE-2026-82078 urgently, and inspect PaperCut and server logs for unusual sign-ins, command execution, or reconnaissance activity.
  • Do not: Ignore vendor or agency advisories on actively exploited vulnerabilities. Prompt action within the recommended timeframe reduces exposure significantly.
  • Report: If PaperCut is present and you find signs of exploitation or unexpected activity, escalate to your IT provider immediately and report suspected active exploitation to NCSC NZ at report.ncsc.govt.nz.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.