PaperCut Is Being Actively Exploited Right Now: What UK Small Businesses Need to Do Today
Two vulnerabilities in PaperCut NG and MF were added to CISA’s Known Exploited Vulnerabilities catalogue on 31 August 2026. Not flagged as theoretical. Not described as requiring sophisticated actors. Actively exploited. Right now.
This is today’s brief. We are going to cover what these vulnerabilities actually do, why the patch situation is messier than a single update, and what a small business owner needs to do before the end of the working day.
What PaperCut Is and Why You Probably Have It
PaperCut NG and MF are print management platforms. They sit on a server, talk to your printers, and handle things like print quotas, job queuing, access control, and watermarking. They are common in schools, professional services firms, accountancy practices, solicitors’ offices, and any organisation where controlled printing matters.
If your business has more than a handful of staff and manages printing centrally, there is a reasonable chance PaperCut is somewhere in your environment. If you use a managed service provider, there is also a reasonable chance they installed it and you have not thought about it since.
That is the problem.
What the Vulnerabilities Actually Do
CVE-2026-81578 is an authentication bypass. The CISA description is straightforward: an unauthenticated remote attacker can modify certain system configurations by accessing admin functions through the web interface. No login required. No credentials to steal first. An attacker with network access to your PaperCut server can walk straight in.
CVE-2026-82078 is what happens next. It is an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode under the security context of the PaperCut server process. In plain terms: once inside via the first vulnerability, an attacker can run code on your server with the permissions of the PaperCut service account.
These two vulnerabilities are designed to be chained. The first one opens the door. The second one lets the attacker do whatever they want once they are through it.
CISA confirmed both are being actively exploited in the wild as of 31 August 2026.
Why the Patch Situation Is More Complicated Than Usual
PaperCut issued an initial emergency patch the week of 27 August 2026. That patch has already been broken. Security researchers demonstrated within days that the fix was incomplete, prompting PaperCut to issue a second emergency patch.
This matters for two reasons.
First, if your MSP or IT team applied the initial patch and considered the job done, they need to go back. The second patch is the one that counts.
Second, the fact that researchers broke the first fix quickly tells you something about the severity of the underlying issue. This is not a minor edge case. The vulnerability is significant enough that skilled researchers could circumvent the initial remediation without much difficulty.
PaperCut’s security bulletin from 27 August 2026 is the reference point. The second emergency patch is documented there. Check the version numbers against what is running in your environment.
The MSP Problem
If you use a managed service provider, your first instinct might be to assume they have handled this. That assumption is worth testing.
MSPs manage multiple clients simultaneously. Patch deployment priorities vary. Communication about what has been patched and when is inconsistent across the industry. Some MSPs are excellent. Some are not. The ones who are not excellent do not tend to advertise that fact.
Ask your MSP today, in writing, whether the second PaperCut emergency patch has been applied to your environment. Ask for the version number that is currently running. Ask when the patch was applied. If they cannot answer those questions specifically and quickly, that is information worth having about the quality of your managed service.
If you manage your own IT, the same question applies but directed inward. What version of PaperCut NG or MF is currently running? When was it last updated?
The Manic Android Trojan: A Secondary Signal Worth Noting
Separate from the PaperCut situation, Kaspersky published research on 31 August 2026 on a new Android malware family called Manic. It steals banking credentials and SMS codes, takes remote control of infected devices, and does so through a transparent capture layer that sits over the device’s keyboard.
The detail that warrants attention for small businesses is the offline capability. Manic can steal credentials and relay stolen information through other infected devices without requiring a direct internet connection. It uses infected phones as relay nodes.
For a small business owner, the relevant question is straightforward: are staff accessing business banking, business email, or cloud services from personal Android devices? If yes, that is an attack surface that sits entirely outside your IT controls. A compromised personal device becomes a credential harvester that your firewalls and endpoint tools cannot see.
This is not a reason to panic. It is a reason to have a clear mobile device policy and to ensure that business-critical authentication does not rely solely on SMS codes sent to personal phones.
How This Gives You an Edge
Small businesses that respond quickly to CISA KEV additions are objectively better positioned than those that do not. The KEV list is the clearest available signal of real-world exploitation. It is not vendor marketing. It is not theoretical risk modelling. It is a government agency saying: this vulnerability is being used against real targets right now.
If you can demonstrate to clients and procurement contacts that your business monitors the KEV list and acts on additions promptly, that is a verifiable security posture. It is the kind of thing that differentiates a business during supplier due diligence in regulated sectors: legal, financial services, healthcare supply chains, public sector contracts.
Most small businesses cannot answer the question “how do you know when a critical vulnerability is being actively exploited?” You now have an answer.
Making the Business Case
If you need to justify urgent action to a director, a board, or a budget holder, these are the three points that land:
The threat is confirmed, not theoretical. CISA’s Known Exploited Vulnerabilities catalogue requires evidence of active exploitation before a vulnerability is added. This is not a vendor’s threat report with inflated numbers. It is a government agency confirming that real attackers are using these vulnerabilities against real targets.
The first patch failed. PaperCut issued one emergency fix. Researchers broke it. A second patch is now available. This is not routine maintenance. The urgency is proportionate to the situation.
Print servers are often trusted inside networks. PaperCut typically runs on a server with broad network access to printers, workstations, and file shares. An attacker who compromises a PaperCut server is not stuck in a corner. They are in a position to move laterally through the network. The blast radius of a successful exploitation is larger than the name “print management software” might suggest.
What to Do Before End of Day
-
Determine whether PaperCut NG or MF is running in your environment. If you are not sure, ask your MSP or IT contact directly. The question is: do we run PaperCut, and if so, what version?
-
Check the version number against PaperCut’s security bulletin from 27 August 2026. The bulletin specifies the minimum patched versions for both NG and MF. If your version is below the threshold, the second emergency patch has not been applied.
-
Contact your MSP in writing and ask for confirmation of patch status. Email is fine. The point is to create a record of the question and the response. If the patch has not been applied, ask for a timeline. Same day is appropriate given CISA’s confirmation of active exploitation.
-
If PaperCut is internet-facing, restrict access immediately. The attack does not require authenticated access. If the PaperCut web interface is reachable from outside your network, restrict it to internal access only until the patch is confirmed applied.
-
Review your mobile device policy. In light of the Manic Android trojan research, check whether staff are authenticating to business systems via personal Android devices. If SMS-based two-factor authentication is in use for business banking or cloud services, consider whether hardware tokens or authenticator apps would reduce the exposure.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share it with someone who would find it useful. The people who need this information most are often the ones who are not yet listening.