In summary: PaperCut has issued an emergency patch to address two vulnerabilities in its NG/MF print server that attackers are already exploiting. If you are running this software, apply the patch today—not during the next maintenance window.
What Happened
On August 27, 2026, the software vendor PaperCut issued a security bulletin classified as urgent. It addresses two vulnerabilities that work in combination: CVE-2026-81578 allows authentication to be bypassed, while CVE-2026-82078 allows remote code execution on the server. The vendor reports a CVSS score of 9.4 out of 10 for the second vulnerability.
The game-changer: PaperCut reports that these vulnerabilities are being actively exploited. This is not a lab-based discovery. Teams at Huntress and Rapid7 documented actual exploits as early as August 28. CERT-FR published its advisory on the same day, under reference CERTFR-2026-AVI-1095, and then updated it on August 31 with new indicators of compromise.
This affects all versions of PaperCut MF and NG prior to branches 24, 25, and 26 that have not received the vendor's temporary fix. This fix blocks SQL queries containing the EXEC, EXECUTE, or CALL statements when searching for card numbers from an external database.
Does this apply to me?
PaperCut manages and bills for printing. It is widely used in small and medium-sized businesses with multiple locations, local governments, schools, and accounting or law firms. It was often installed several years ago by the copier service provider and then forgotten. This is precisely the problem: a Windows server running on its own, rarely updated, and sometimes exposed to the Internet to allow printing from outside the network.
Two questions are all it takes to settle the matter.
Do we have it? The service is called PaperCut Application Server, and its process is named pc-app.exe. Your printing service provider or IT service provider can get back to you in two minutes.
Can it be accessed from the outside? By default, the administration console listens on ports 9191 and 9192. If either port responds from the Internet, consider the server exposed and move this issue to the top of the list.
If PaperCut isn't deployed at your organization, this alert doesn't apply to you. It's still a good test: being able to answer within a few minutes, "Is this software running at our organization?"—that's the real question every bulletin of this type raises.
What to Do Now
- Apply the vendor patch. It has been available since August 27 for branches 24, 25, and 26. This is a high-priority action that must be completed before any analysis.
- Close the exposure if the fix has to wait. PaperCut recommends restricting access to the application server to trusted IP addresses via a firewall rule. Take this opportunity to remove any direct exposure to the Internet: remote printing works best through a VPN.
- Look for signs of an attack. CERT-FR lists several indicators: abnormal activity in the pc-app.exe process; missing, truncated, or deleted server.log files; and the presence of the error messages “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST” in these logs. The publisher notes that the absence of these indicators does not prove anything. If in doubt, treat the event as an incident and seek assistance.
This reasoning applies beyond PaperCut. A vulnerability warrants urgent attention when it meets three conditions: it is being actively exploited in the wild, it does not require prior authentication, and the affected service is accessible from the outside. PaperCut checks all three boxes this week. The vast majority of CVEs that come up do not meet any of these criteria and can wait for the normal update cycle.
If no one in the company can say who applies the patches to the application servers, that's the core issue. A quick consultation with an expert is often enough to get a handle on it.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
Two PaperCut vulnerabilities were fixed on August 27 and have already been exploited. If you're running the software, apply the patch and disconnect it from the Internet. Otherwise, no action is needed.
An alert of this level can be resolved in half a day as long as the inventory is up to date and someone has direct access to the servers. That's what this week is really putting to the test.
Frequently asked questions
Can our printers be hacked? The vulnerability targets the PaperCut server, not the printers themselves. The risk isn't printing itself, but rather access to the Windows server hosting the application—and whatever that server can then access.
We're using Microsoft 365—are we protected? No. PaperCut is an application installed on your own servers and updates independently of your Microsoft environment.
Should you notify the CNIL? Only if you discover a data breach involving personal information. Detection comes first; notification, if required, must be made within 72 hours.
— Samir Amara, CEO — IT Systèmes




.jpeg)

