We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

PaperCut Vulnerability Exploited (CVE-2026-82078): Is Your Print Server Affected?

On August 27, 2026, PaperCut released an emergency patch for two vulnerabilities in its NG and MF print servers, which had already been exploited by attackers. CERT-FR relayed the alert and updated it on August 31 with new indicators. Here’s how to find out in just a few minutes if your company is affected—and what to do in the hours that follow.

PaperCut Vulnerability Exploited (CVE-2026-82078): Is Your Print Server Affected?

In summary: PaperCut has issued an emergency patch to address two vulnerabilities in its NG/MF print server that attackers are already exploiting. If you are running this software, apply the patch today—not during the next maintenance window.

What Happened

On August 27, 2026, the software vendor PaperCut issued a security bulletin classified as urgent. It addresses two vulnerabilities that work in combination: CVE-2026-81578 allows authentication to be bypassed, while CVE-2026-82078 allows remote code execution on the server. The vendor reports a CVSS score of 9.4 out of 10 for the second vulnerability.

The game-changer: PaperCut reports that these vulnerabilities are being actively exploited. This is not a lab-based discovery. Teams at Huntress and Rapid7 documented actual exploits as early as August 28. CERT-FR published its advisory on the same day, under reference CERTFR-2026-AVI-1095, and then updated it on August 31 with new indicators of compromise.

This affects all versions of PaperCut MF and NG prior to branches 24, 25, and 26 that have not received the vendor's temporary fix. This fix blocks SQL queries containing the EXEC, EXECUTE, or CALL statements when searching for card numbers from an external database.

Does this apply to me?

PaperCut manages and bills for printing. It is widely used in small and medium-sized businesses with multiple locations, local governments, schools, and accounting or law firms. It was often installed several years ago by the copier service provider and then forgotten. This is precisely the problem: a Windows server running on its own, rarely updated, and sometimes exposed to the Internet to allow printing from outside the network.

Two questions are all it takes to settle the matter.

Do we have it? The service is called PaperCut Application Server, and its process is named pc-app.exe. Your printing service provider or IT service provider can get back to you in two minutes.

Can it be accessed from the outside? By default, the administration console listens on ports 9191 and 9192. If either port responds from the Internet, consider the server exposed and move this issue to the top of the list.

If PaperCut isn't deployed at your organization, this alert doesn't apply to you. It's still a good test: being able to answer within a few minutes, "Is this software running at our organization?"—that's the real question every bulletin of this type raises.

What to Do Now

  1. Apply the vendor patch. It has been available since August 27 for branches 24, 25, and 26. This is a high-priority action that must be completed before any analysis.
  2. Close the exposure if the fix has to wait. PaperCut recommends restricting access to the application server to trusted IP addresses via a firewall rule. Take this opportunity to remove any direct exposure to the Internet: remote printing works best through a VPN.
  3. Look for signs of an attack. CERT-FR lists several indicators: abnormal activity in the pc-app.exe process; missing, truncated, or deleted server.log files; and the presence of the error messages “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST” in these logs. The publisher notes that the absence of these indicators does not prove anything. If in doubt, treat the event as an incident and seek assistance.

This reasoning applies beyond PaperCut. A vulnerability warrants urgent attention when it meets three conditions: it is being actively exploited in the wild, it does not require prior authentication, and the affected service is accessible from the outside. PaperCut checks all three boxes this week. The vast majority of CVEs that come up do not meet any of these criteria and can wait for the normal update cycle.

If no one in the company can say who applies the patches to the application servers, that's the core issue. A quick consultation with an expert is often enough to get a handle on it.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

Two PaperCut vulnerabilities were fixed on August 27 and have already been exploited. If you're running the software, apply the patch and disconnect it from the Internet. Otherwise, no action is needed.

An alert of this level can be resolved in half a day as long as the inventory is up to date and someone has direct access to the servers. That's what this week is really putting to the test.

Frequently asked questions

Can our printers be hacked? The vulnerability targets the PaperCut server, not the printers themselves. The risk isn't printing itself, but rather access to the Windows server hosting the application—and whatever that server can then access.

We're using Microsoft 365—are we protected? No. PaperCut is an application installed on your own servers and updates independently of your Microsoft environment.

Should you notify the CNIL? Only if you discover a data breach involving personal information. Detection comes first; notification, if required, must be made within 72 hours.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Custom Software Development Providers for Small and Medium-Sized Businesses and Mid-Size Companies
Development & automation

Top Custom Software Development Providers for Small and Medium-Sized Businesses in France in 2026

Which company can develop your custom business software? A comparison of four French service providers based on market positioning, starting price, and turnaround time, for small and medium-sized businesses.
September 2, 2026
Cybersecurity

Hello, E.Leclerc: The leak came from a service provider—here’s what an SME should check with its own staff

LCommerce, the company that operates the Allo E.Leclerc service, has informed some of its customers that one of its external logistics providers had been hacked. Names, email addresses, and phone numbers were compromised, but no banking information was exposed. The incident was reported to the CNIL and serves as a reminder that a company can be affected even if its own system has not been compromised.
September 1, 2026
Helpy Barometer: Resolution rate for Level 1 tickets measured on the IT Systèmes internal help desk
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

Helpy 2026 Barometer: 44% of Level 1 tickets resolved without human intervention

44% of Level 1 tickets resolved without human intervention, 3-minute average resolution time, €0.26 per ticket. Eleven months of data collected from our own help desk, including methodology and limitations.
September 1, 2026
IT Security Governance and Steering Meeting in an Open-Plan Office
Cybersecurity

Cybersecurity GRC: Governance, Risk, and Compliance—A Guide for Small and Medium-Sized Businesses

GRC (Governance, Risk, and Compliance) provides a framework for managing IT security. Definition, clarification of differences from CRM, pillars, relationship with NIS2, and implementation for small and medium-sized businesses and mid-sized companies.
August 27, 2026
Cybersecurity

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a widely used dashboard tool among small and medium-sized businesses. A few days earlier, the French service provider TeleCoop confirmed that its own instance had been compromised. How to decide whether your company should apply the patch today or next week.
August 27, 2026
Abstract illustration of a data flow related to an artificial intelligence platform
Cybersecurity

Claimed Data Breach at Klark.ai: The Real Risk for Small and Medium-Sized Businesses Using AI Tools

A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform dedicated to customer service. Approximately 500,000 people are reportedly affected, with support conversations, API keys, and a few IBANs among the stolen data. Here’s how to tell if your small business is indirectly at risk—and the three checks you should perform this week.
August 27, 2026