Live Feeds
● TRACKER Updated 3d ago · 16 sources tracked

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has issued official security maintenance releases for NG/MF versions 26.0.5, 25.0.13, and 24.1.10 to resolve two actively exploited vulnerabilities. These updates replace the three previous emergency patches and include additional security hardening after undergoing full QA testing. The fixes address CVE-2026-81578 and CVE-2026-82078, which were used in an automated campaign involving AI agents to compromise 440 servers across 395 organizations. Security teams should migrate from emergency patches to these stable maintenance releases immediately to secure their environments.

RSS Source map (17)

What changed

PaperCut replaced its emergency patches with fully tested maintenance releases for versions 26.0.5, 25.0.13, and 24.1.10.

Live updates

  1. PaperCut Releases Formal Maintenance Updates to Replace Emergency Patches

    PaperCut has issued official security maintenance releases for NG/MF versions 26.0.5, 25.0.13, and 24.1.10 to resolve two actively exploited vulnerabilities. These updates replace the three previous emergency patches and include additional security hardening after undergoing full QA testing. The fixes address CVE-2026-81578 and CVE-2026-82078, which were used in an automated campaign involving AI agents to compromise 440 servers across 395 organizations. Security teams should migrate from emergency patches to these stable maintenance releases immediately to secure their environments.

    Why it matters

    Huntress first detected the exploitation of these flaws on August 26 via base64-encoded commands. The attack chain allows for remote code execution, enabling threat actors to move from initial access to Active Directory compromise.

    What is confirmed

    • PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available as Regular Maintenance Releases.
    • The new releases contain all security fixes from Emergency Patch Releases 1, 2 and 3.
    • AI agents were used to exploit PaperCut flaws across 440 servers.
    • The campaign targeted vulnerabilities CVE-2026-81578 and CVE-2026-82078.

    Still unconfirmed

    • A Russian threat actor is responsible for the AI-powered attacks.
    • Huntress identified the initial anomalous activity on August 26.

    What to watch next

    • Confirmation of patch adoption rates across the 395 affected organizations
    • Identification of additional IP addresses linked to the AI agent infrastructure
    Sources used for this update (4)
    1. thehackernews.com — PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
    2. www.techrepublic.com — AI Agents Help Hackers Compromise 440 PaperCut Servers
    3. www.securityweek.com — PaperCut Flaws Exploited in AI-Powered Attacks
    4. tech.yahoo.com — The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory
    confidence 90%
  2. Russian-speaking actor uses AI agents to compromise 440 PaperCut servers

    A suspected Russian-speaking threat actor used hundreds of autonomous AI agents to exploit CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF. The campaign, tracked since August 31, 2026, compromised at least 440 servers across 395 organizations in 48 countries. Attackers used LLM-powered automation to accelerate operations from initial reconnaissance to Active Directory compromise. Blackpoint Cyber and GreyNoise linked the activity to IP address 45.142.193[.]132, which Arctic Wolf previously associated with the exploitation of these vulnerabilities. PaperCut has issued emergency patches and recommends restricting web access to trusted networks.

    Why it matters

    The attack targets an authentication bypass and remote code execution chain. Previous reports identified victims as schools and universities in Europe and the US. The use of AI orchestration marks a shift in how attackers scale initial access operations.

    What is confirmed

    • A likely Russian-speaking threat actor used hundreds of AI agents to compromise at least 440 servers across 395 organizations in 48 countries.
    • The campaign targeted the CVE-2026-81578 and CVE-2026-82078 vulnerability chain.
    • The activity is linked to IP address 45.142.193[.]132.
    • PaperCut released emergency patches and advised restricting application-server web access to trusted networks.

    Still unconfirmed

    • Nevan Beal of Blackpoint cannot confirm if the actor is operating as an initial access broker.

    What to watch next

    • Verification of the AI orchestration claims by independent security researchers.
    Sources used for this update (5)
    1. letsdatascience.com — Threat Actor Reportedly Deploys AI Agents Against PaperCut
    2. cyberpress.org — Hackers Deploy Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers
    3. www.bleepingcomputer.com — AI-powered attack exploited PaperCut flaws to hack 395 organizations
    4. thehackernews.com — PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
    5. thecyberexpress.com — AI Agents Compromised 440 PaperCut Servers, Researchers Say
    confidence 90%
  3. Attackers Target US and European Education Sector via PaperCut Zero-Days

    Threat actors are using an authentication bypass and remote code execution chain in PaperCut NG and MF to steal credentials from schools and universities in the US and Europe. The Arctic Wolf Adversary Research Team and researchers Jens Pose and Ross Phillips report that attackers are executing commands, conducting reconnaissance, and creating privileged accounts. Post-exploitation activity includes deploying Metasploit Meterpreter Java payloads and tools to collect Windows registry hives. These attacks follow PaperCut's August 27 disclosure of active exploitation of CVE-2026-81578 and CVE-2026-82078.

    Why it matters

    The vulnerability affects all versions of PaperCut NG and MF, leaving nearly half of enterprise installations exposed. This exploit chain allows attackers to transition from initial access to full system manipulation. The targeting of the education sector indicates a shift toward specific high-value institutional targets.

    What is confirmed

    • Attackers are exploiting CVE-2026-81578 and CVE-2026-82078 to conduct command execution and reconnaissance.
    • The exploit chain allows threat actors to create privileged accounts on affected PaperCut servers.
    • Observed post-exploitation activity includes the delivery of Metasploit Meterpreter-related Java payloads.
    • PaperCut disclosed the active exploitation of these flaws on August 27.

    Still unconfirmed

    • The PaperCut exploit chain has hit 70,000 organizations.
    • Nearly half of enterprise installations remain exposed to the authentication gap.

    What to watch next

    • Confirmation of specific victim counts within the US and European education sectors
    • Release of detailed indicators of compromise for the Windows registry hive collection tools
    Sources used for this update (11)
    1. thehackernews.com — Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
    2. thehackernews.com — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    3. thehackernews.com — Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
    4. cyberpress.org — Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
    5. thehackernews.com — Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
    6. thehackernews.com — Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
    7. forkast.news — PaperCut’s Authentication Gap Returns: Two-Minute RCE Chain Hits 70,000 Organizations
    8. thehackernews.com — ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
    9. www.bleepingcomputer.com — Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
    10. thehackernews.com — JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
    11. cyberpress.org — Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day for Unauthenticated RCE
    confidence 90%
  4. PaperCut Zero-Day Exploitation Continues Amid Broad Software Vulnerabilities

    Attackers continue to use CVE-2026-81578 and CVE-2026-82078 for manual system manipulation and data theft across all PaperCut NG and MF versions. While patches exist, CISA reports that hackers have moved beyond automated scripts to hands-on-keyboard intrusions. This activity coincides with a wider wave of exploits, including a high-severity V8 type confusion bug in Google Chrome and remote code execution flaws in SonicWall SMA1000 devices. Organizations must prioritize patching PaperCut instances and updating Chrome to version 152.0.7977.82 to mitigate active remote code execution risks.

    Why it matters

    PaperCut software manages printing across corporate networks, making these flaws a gateway for deep network access. The shift from scripts to manual intrusion indicates sophisticated actors targeting specific environments. These attacks occur as AI capabilities, such as GPT-6 Astra, demonstrate near-perfect scores on exploit benchmarks.

    What is confirmed

    • CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog.
    • PaperCut NG and MF vulnerabilities affect all versions of the software.
    • Google released a patch for CVE-2026-85046, a high-severity type confusion bug in the V8 engine.
    • The Chrome V8 vulnerability allowed remote attackers to execute arbitrary code inside the sandbox via a crafted HTML page.
    • SonicWall SMA1000 vulnerabilities CVE-2026-83549 and CVE-2026-83548 allow remote code execution and are being exploited.

    Still unconfirmed

    • Plex released updates for Media Server 1.43.3 and Desktop 1.115.0 to patch undisclosed security flaws.

    What to watch next

    • Release of CVE identifiers for the undisclosed Plex security flaws.
    Sources used for this update (5)
    1. www.securityweek.com — SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
    2. thehackernews.com — GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
    3. thehackernews.com — Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
    4. thehackernews.com — Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
    5. www.bleepingcomputer.com — Google warns of new Chrome zero-day flaw exploited in attacks
    confidence 95%
  5. CISA Adds PaperCut Zero-Days to Known Exploited Vulnerabilities Catalog

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog. Attackers are now using these flaws to conduct data theft and hands-on-keyboard intrusions. These vulnerabilities affect all versions of PaperCut NG and MF print management software. While patches were released last week, active exploitation continues as hackers move beyond automated scripts to manual system manipulation.

    Why it matters

    These vulnerabilities allow attackers to bypass authentication and execute remote code. A Metasploit module has lowered the barrier for entry, leaving nearly half of tracked installations exposed.

    What is confirmed

    • CISA added PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog.
    • Attackers are using CVE-2026-81578 and CVE-2026-82078 to steal data.

    Still unconfirmed

    • Hackers are performing hands-on-keyboard activity during PaperCut attacks.

    What to watch next

    • Updates on the percentage of installations patched since the CISA warning
    • Reports of specific organizations targeted for data theft
    Sources used for this update (4)
    1. securityaffairs.com — U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
    2. www.securityweek.com — PaperCut Exploitation Escalates to Active Intrusions
    3. www.bleepingcomputer.com — Recently patched PaperCut zero-days used in data theft attacks
    4. cyberpress.org — CISA Warns of Two PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks
    confidence 100%
  6. PaperCut Zero-Day Chain Exploited via Metasploit as 47% of Servers Remain Unpatched

    Attackers are using a chain of zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and execute remote code on PaperCut NG and MF servers. A new Metasploit Framework module created by Stephen Fewer makes these exploits more accessible. Despite two emergency patches, 47% of tracked installations remain vulnerable. Compromised internet-facing servers are being loaded with legitimate remote access software to maintain persistence. PaperCut confirmed customer incidents shortly before the Metasploit module was submitted.

    Why it matters

    The vulnerabilities affect all versions of the print management software. This follows a 2023 wave of attacks that specifically targeted higher education customers. The current exploit chain allows unauthenticated access to critical server functions.

    What is confirmed

    • The exploited vulnerabilities are identified as CVE-2026-82078 and CVE-2026-81578.
    • The vulnerability chain combines authentication bypass with remote code execution.
    • PaperCut has released a second emergency patch for these flaws.
    • Stephen Fewer submitted pull request #21842 to the Metasploit Framework to target the PaperCut zero-day chain.

    Still unconfirmed

    • 47% of tracked PaperCut installations are still running unpatched versions.
    • Threat actors are installing legitimate remote access software on compromised internet-facing servers.

    What to watch next

    • Confirmation of specific industries currently being targeted.
    Sources used for this update (5)
    1. securityaffairs.com — Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
    2. www.securityweek.com — More Details Emerge on Exploited PaperCut Vulnerabilities
    3. www.cybersecuritydive.com — PaperCut issues emergency patches as threat actors target chained vulnerabilities
    4. cyberpress.org — Metasploit Exploit Targets Actively Exploited PaperCut NG/MF Zero-Day RCE Chain
    5. www.helpnetsecurity.com — Attackers plant remote access tools on compromised PaperCut servers
    confidence 90%
  7. PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

    Attackers are exploiting a zero-day vulnerability in PaperCut, affecting all NG and MF versions. The vulnerability allows for code execution without authentication. PaperCut has released emergency patches to address the issue. Multiple sources confirm the exploitation and patch releases.

    Why it matters

    The exploitation of the PaperCut zero-day vulnerability highlights the ongoing threat of unpatched software vulnerabilities being targeted by attackers. PaperCut is a popular print management software used in various organizations. The vulnerability's exploitation could lead to unauthorized access and potential data breaches. This incident emphasizes the importance of timely patching and software updates.

    What is confirmed

    • The zero-day vulnerability affects all PaperCut NG and MF versions.
    • Attackers can chain two PaperCut flaws to execute code without authentication.
    • PaperCut has released emergency patches to address the exploited zero-day vulnerability.
    • Multiple sources confirm the exploitation of the PaperCut zero-day vulnerability.

    What to watch next

    • Further updates on the impact of the vulnerability on specific organizations
    • Releases of additional patches or updates by PaperCut
    • Investigations into the attackers' motives and identities
    Sources used for this update (5)
    1. The Hacker News — PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
    2. The Hacker News — Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
    3. SecurityWeek — PaperCut Releases Emergency Patch for Exploited Zero-Day
    4. Printweek — PaperCut targeted by hackers
    5. BleepingComputer — PaperCut releases second emergency patch for exploited flaws
    confidence 100%