TechNewsReel
Live

PaperCut Zero-Days Fuel Active Data Theft Campaigns

Attackers are leveraging previously unknown flaws in widely used print management software to exfiltrate sensitive organizational data.

TechNewsReel Newsroom · September 1, 2026

Two security vulnerabilities in PaperCut NG and MF print management software are being actively exploited in data theft attacks, according to BleepingComputer. These flaws were utilized as zero-days before patches were available, allowing attackers to bypass security measures and gain unauthorized access to corporate systems.

Security reports indicate that threat actors are using these vulnerabilities to infiltrate networks and exfiltrate sensitive information. Because the flaws were exploited in the wild before the vendor could release fixes, the window for undetected intrusion was significant, leaving many organizations vulnerable to silent compromise.

The Infrastructure Target

PaperCut NG and MF are industry-standard print management solutions designed to help organizations monitor and control printing costs and workflows. Because this software typically sits deep within a corporate network and interacts with various user directories and hardware, it represents a high-value target for attackers. Gaining a foothold through infrastructure software often provides a stealthy path for initial access, allowing hackers to move laterally through a network to reach more critical assets.

Implications for Corporate Security

The shift from initial exploitation to active data theft suggests a sophisticated and targeted campaign. The primary risk is that many organizations may have been compromised long before the vulnerabilities were publicly disclosed or patched. When zero-days are used in this manner, traditional perimeter defenses are often ineffective, and the theft of data may only be discovered long after the breach has occurred.

Next Steps for Administrators

Organizations using PaperCut NG or MF are urged to ensure they have applied the most recent security patches immediately. Security teams should also conduct retrospective log analysis to identify signs of unauthorized access or unusual data egress that may have occurred prior to patching. While the vulnerabilities have been addressed by the vendor, the ongoing nature of the data theft attacks means that patching alone may not be sufficient for those already compromised; a full incident response review is recommended to ensure no persistence remains within the environment.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.