Two PaperCut Zero-Days Hit CISA KEV With Two-Week Patch Window
# Two PaperCut Zero-Days Hit CISA KEV With Two-Week Patch Window
Listen, kid. You’re probably staring at your dashboard and wondering why you should care about a print management tool when there are AI agents going off the rails and routers getting backdoored. It looks boring. Printing is boring. But in this job, "boring" is where the blood is.
The boring stuff—the legacy servers, the forgotten utility boxes, the software that does one thing and hasn't changed its UI since 2012—is exactly where attackers set up shop. Right now, PaperCut NG and MF are the prime examples. CISA just slapped CVE-2026-82078 and CVE-2026-81578 on the Known Exploited Vulnerabilities list on August 31. They've given federal agencies a deadline of September 14 to patch. That's a two-week window.
In plain terms, we're looking at an unsafe reflection flaw and a missing authentication vulnerability. To a suit, that sounds like a technical glitch. To us, it means there are ways to trick the system into executing code or accessing critical functions without needing a password. It’s essentially leaving the back door propped open with a brick and putting up a sign that says "Admin Access This Way."
Who actually runs this? Everyone. Every school district, every mid-sized law firm, and half the government offices in the country use PaperCut to stop people from printing 500 pages of personal photos on company ink. These servers usually sit in some neglected VLAN, running on a VM that hasn't been rebooted since the last leap year because the IT manager is terrified that if it goes down, the accounting department will stage a coup.
Exploitation here isn't about the printer; it's about the beachhead. Once an attacker lands on a print server, they aren't looking for PDF files. They’re looking for service accounts. Print servers often have high-privilege hooks into Active Directory to handle user authentication and quotas. If I can pop your PaperCut box, I don't need to be "sophisticated." I just need to dump the memory, find a credential, and pivot straight to your domain controller.
I saw this play out during NotPetya. The world was screaming about the initial vector, but the real carnage happened because of how quickly things moved laterally once they hit a trusted internal service. This is the same physics.
Now, you'll hear some analyst tell you that patching is straightforward because the vendor released the fix. They’re wrong. Patching a print server in a production environment is rarely "straightforward." You have to coordinate with people who view "downtime" as a personal attack. You've got legacy drivers that might break. You've got owners who forgot where the server is even hosted.
But here is the real risk—the second-order effect. Think about your Managed Service Providers (MSPs). There are hundreds of MSPs managing print infrastructure for dozens of small clients each. If an MSP has a centralized management console or a shared deployment pipeline that's vulnerable, the blast radius isn't one office; it's every single one of their customers. One unpatched box at the provider level is a skeleton key for fifty different networks.
The counter-argument you’ll hear from the lazy ones is that the print server is isolated. "It's on its own subnet, Ray. It can't talk to the core."
I've spent twenty years watching "isolated" subnets get bridged by a single rogue crossover cable or a misconfigured firewall rule created by an intern in 2019. Isolation is a fairy tale we tell ourselves so we can sleep on Tuesday nights. If it has an IP address and it's running an exploited service, it's a liability.
Look at the Cl0p campaign hitting PTC Windchill. They’ve already named north of 40 victims. Those attackers don't care about the product; they care about the access. When you see two CVEs hit the KEV list simultaneously for one product, it means the exploit chain is mature. The criminals have already done the hard work. All they need now is for you to be slow.
If you're seeing a "sophisticated" attack in your logs, stop using that word. It's an excuse for poor hygiene. There is nothing sophisticated about using a known flaw that CISA has already flagged. It's just basic arithmetic: if the cost of exploitation is lower than the cost of patching, the attacker wins every time.
Check your assets. If you find a PaperCut instance, don't ask who manages it. Just tell them they have until September 14 before the blast radius becomes their problem.
I’ll be at my desk. Bring me a coffee that actually tastes like coffee.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure The Hacker News
- Hackers Start Exploiting Critical Langflow Vulnerability SecurityWeek
- Attackers Pounce on Critical Artifactory Flaw Following Disclosure Dark Reading
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials The Hacker News
- McKesson Data Breach Exposes Millions to Patient Data Theft - The Cryptonomist Google News Security
- FBI Probes Service Selling 153M+ Drivers Licenses Krebs on Security
- PaperCut warns of active attacks targeting its print software - Escudo Digital Google News Security
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain The Hacker News