Managed IT · September 2026
The server nobody thinks about is the one attackers want
Almost nobody has "print server" on their risk register. Attackers have noticed.
On August 27, 2026, PaperCut published an urgent advisory confirming that its NG and MF print management software was under active attack. Two flaws, CVE-2026-81578 and CVE-2026-82078, could be chained by an attacker with no credentials at all: the first lets them alter system configuration, the second lets them load and run arbitrary code. CISA added both to its Known Exploited Vulnerabilities catalog on August 31. In the attacks actually observed, the intruders were not making noise, they were quietly dumping database tables and taking the data.
This is not the first time. The same product line was a ransomware on-ramp in 2023. And the software itself is not really the story.
Why the quiet servers are the dangerous ones
Ask a small business owner to list their critical systems and you will hear about the file server, the accounting system, and email. You will almost never hear "the print server." It is the box in the closet that has been running fine for six years. Nobody logs into it. Nobody thinks about it.
But it is domain-joined. It holds credentials. It often has a management interface reachable from more of the network than anyone realizes. It is, in other words, an excellent place to land, and a terrible place to be blind.
The five-minute test
Here is a question worth putting to whoever handles your IT, today: when was our print server last patched?
If the answer takes more than five minutes to produce, the problem is not PaperCut. The problem is that you have systems nobody owns. And the same test applies to every other quiet machine on your network: the backup appliance, the door access controller, the old application server that one department still depends on, the network video recorder.
What ownership actually means
- Every device has a named owner, a purpose, and a recorded patch status
- Somebody receives vendor security advisories for it, and reads them
- It appears on a list that gets reviewed, not in somebody's memory
- When a critical advisory lands, there is a known path to patching it inside days, not at the next convenient maintenance window
Inventory is unglamorous and it is the whole game
There is no product you can buy that fixes not knowing what you own. Asset inventory is the least exciting item in security and it quietly determines whether everything else works. A patch you never apply because you forgot the machine exists is not a patch.
Most of the organizations we take on have at least one system like this, and finding them is a standard part of our free assessment. It is usually the cheapest risk anyone reduces all year.
The five-minute test
Ask whoever handles your IT today: when was our print server last patched? If that takes more than five minutes to answer, the problem is not the software.
Get started
Questions about your own setup?
A free assessment turns general guidance into specific next steps for your organization. No pressure, no obligation.