PaperCut Flaws Exploited in AI-Powered Attacks
GreyNoise says a Russian-speaking actor used AI to build and deploy exploits hitting 440 PaperCut NG/MF deployments across 395 organizations in 48 countries.
Two PaperCut NG/MF zero-days, CVE-2026-82078 and CVE-2026-81578, disclosed August 27 and patched August 28, enable unauthenticated authentication bypass and remote code execution. GreyNoise observed a Russian-speaking threat actor using AI to orchestrate attacks against 440 deployments in 48 countries, including 204 education-sector organizations, achieving domain admin at 12 victims. Attack paths included harvesting LSASS memory and registry secrets, mounted NoPac attacks, and adding accounts to Domain Admins, with AI automation shortening compromises to minutes or seconds.
- CVE-2026-82078 and CVE-2026-81578 allow unauthenticated bypass and code execution
- 440 deployments attacked in 48 countries; 204 were education organizations
- Credential harvesting ran on 280 hosts; secrets exfiltrated from 137
- Domain admin achieved at 12 organizations; AI cut compromise times to seconds
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82078 +1 in the same advisory: …81578 | Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attacks CVE-2026-82078 is an unsafe dynamic class loading flaw (unsafe reflection, CWE-470) in the database connection utilities of PaperCut NG and PaperCut MF: the software instantiates a database driver class based on a configurable driver name without validating it against an allowlist of approved drivers. An attacker who can manipulate system configuration parameters can point that setting at classes of their choosing, causing the server to execute arbitrary Java bytecode residing on the application classpath in the security context of the PaperCut server process. On its own the issue is rated 9.4 (Critical) with high privileges required, but when chained with the companion authentication bypass CVE-2026-81578 it yields unauthenticated remote code execution on the print-management server. All PaperCut NG and MF deployments are in scope; affected version ranges were not specified in the available data, so administrators should consult PaperCut's advisory for fixed versions. The flaw is confirmed exploited in the wild as a zero-day: it was added to CISA's KEV catalog on 2026-08-31, and public reporting describes an AI-orchestrated campaign that compromised PaperCut servers at roughly 395 organizations (~440 servers), with EPSS currently at 1.7% (76th percentile). Do: Upgrade PaperCut NG and MF to the patched release specified in PaperCut's security advisory (exact fixed versions were not provided in this data), prioritizing internet-exposed print servers; the KEV listing means agencies must remediate per CISA BOD 26-04 or discontinue/mitigate per its cloud-service guidance. Restrict the PaperCut web interface from direct internet exposure (VPN/allowlist), review administrator accounts and database driver configuration for tampering, and hunt for post-exploitation activity, since this flaw is being actively chained with the authentication bypass CVE-2026-81578. | 9.4 group max | 2% | KEV |
| mass≈100,000+ organizations / plausibly millions of end users (vendor-cited install base); tens of thousands of on-prem servers with a smaller but significant… |
Full article404 words · extracted from securityweek.com · click to collapse
Two recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports.
Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day.
They can allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.
Several days later, WatchTowr threat intelligence head Jake Knott warned that the activity around the two vulnerabilities had been intensifying. Knott believed at the time that initial access brokers were likely behind the exploitation.
This week, threat intelligence firm GreyNoise revealed that a Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG/MF deployments.
The threat actor targeted the vulnerable PaperCut instances of 395 organizations in 48 countries for remote code execution (RCE) and credential harvesting.
Advertisement. Scroll to continue reading.
“There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances,” GreyNoise says.
The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds. The attacker’s success was not even across all organizations, with domain admin achieved against only 12 victim organizations.
“It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment,” GreyNoise notes.
The threat intelligence firm observed three attack paths across the campaign: harvested LSASS process memory and registry secrets from hosts that were domain members, mounted NoPac attacks against unpatched instances, and added a new account to Domain Admins if the host was a Domain Controller.
According to GreyNoise, the attackers performed credential harvesting against 280 of the compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances.
Of the 440 compromised deployments, 204 belonged to organizations in the education sector. Dozens of entities in the retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors were hit as well.
Related: Critical NetScaler Vulnerability Exploited in Attacks
Related: Organizations Warned of Cisco Secure FMC Exploitation
Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/papercut-flaws-exploited-in-ai-powered-attacks/