PaperCut Flaws Exploited in AI-Powered Attacks
Reported exploitedPaperCut NG/MFOur summary
GreyNoise has reported that a Russian-speaking threat actor leveraged AI to orchestrate attacks against hundreds of PaperCut NG/MF installations using CVE-2026-82078 and CVE-2026-81578. These vulnerabilities, patched on August 28 after being disclosed as zero-days, allow unauthenticated remote attackers to bypass authentication and execute arbitrary code. The automated campaign successfully compromised 440 deployments across 395 organizations in 48 countries, facilitating credential harvesting and domain administrator privilege escalation.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.