PaperCut MF Zero-Days Chained to Reach Domain Controller
eSentire says attackers chained two PaperCut MF zero-days on an education print server and copied Active Directory data within two days.
eSentire reported that attackers exploited two PaperCut MF zero-days, CVE-2026-81578 and CVE-2026-82078, on an internet-facing version 24.0.2 server at an education customer. GBHackers identified CVE-2026-81578 as an authentication bypass and CVE-2026-82078 as unsafe dynamic class loading with a CVSS score of 9.4, and said both are in CISA's KEV catalog. Unauthenticated Java execution led to an in-memory loader, a web shell, and an AdaptixC2 implant hidden in trojanized mscopilot.exe. The intrusion was detected on August 31, 2026; within two days the attackers stole a privileged service token, reached a domain controller, used an NTLM hash over RDP, and copied Active Directory through an NTDS.dit IFM backup. The sources agree on the CVEs, product version, sector, and outcome. Emergency patches cover the v24, v25, and v26 branches, the host was isolated, and both reports advise patching and limiting internet exposure.
- Attackers chained PaperCut MF zero-days CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading, CVSS 9.4) on internet-exposed version 24.0.2.
- Both CVEs are in CISA's KEV catalog and were described as actively exploited.
- eSentire detected the education-sector intrusion on August 31, 2026.
- An in-memory loader and web shell were followed by an AdaptixC2 implant inside trojanized mscopilot.exe, a modified Microsoft Copilot binary.
- A domain-privileged service-account token was stolen and a domain controller was reached within two days, including via the PlugPlay service and an NTLM hash over RDP.
- Attackers created an NTDS.dit IFM backup and copied the Active Directory database for offline hash extraction.
- Emergency patches cover the v24, v25, and v26 branches; eSentire isolated the host and advised patching and restricting print-server exposure.
Coverage timelineoldest first · each row is one article
- · 1d agoAttackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
GBHackers· 86
Attackers chained PaperCut MF zero-days CVE-2026-81578 and CVE-2026-82078 to deploy a web shell and dump Active Directory from a domain controller.
- · 23h agoHackers Turned a PaperCut Print Server Into a Path to the Domain Controller
Cyber Security News· 80
Attackers chained two PaperCut MF zero-days to reach an education customer's domain controller in under two days.
Vulnerabilities in this storyAll →
- CVE-2026-820789.44%Unsafe Reflection RCE in PaperCut NG/MF, Chained with Auth Bypass in Attackspublished · PaperCut NG KEV+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-82078+1 related CVE |