Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 53
2 unique sources, 6 articles

Summary

Hide ▲

PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain affecting exposed instances. PaperCut issued a second emergency patch and told operators to remove public internet exposure and restrict PaperCut Application Server access to trusted IPs or a VPN. The latest reporting says a suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits, then compromised at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. Earlier observed post-exploitation activity included a Java `.class` file, Base64-encoded commands, and commands such as `whoami & ver & tasklist` on a PaperCut target.

Related Happenings

JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave

Exploitation Wave
H score42 First: 11.09.2026 19:29 Last: 11.09.2026 19:29 Sources 1

About this happening: Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and depl...

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
H score53 First: 05.09.2026 10:31 Last: 05.09.2026 10:31 Sources 1

How related: At its core, the opportunistic attacks exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, to mainly target the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave
H score55 First: 01.09.2026 20:53 Last: 01.09.2026 20:53 Sources 1

About this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...

PaperCut customer confirmed compromise incidents

Incident
H score41 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.

About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....

Latest development: 01.09.2026 10:48

Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability
H score53 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

About this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...

Timeline

  1. 10.09.2026 14:41 2 articles · 1d ago

    Suspected Russian-speaking actor compromises 440 PaperCut instances with AI agents

    Campaign Scope Update

    A suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

    Show sources
  2. 28.08.2026 20:12 3 articles · 13d ago

    Attackers run whoami, ver, and tasklist on a PaperCut server

    Exploitation Observed

    In an incident recorded on August 27, 2026, threat actors used a different Java `.class` file against a PaperCut target to run `whoami & ver & tasklist`, showing post-exploitation activity after limited exploitation in customer environments.

    Show sources
  3. 28.08.2026 20:12 3 articles · 13d ago

    PaperCut issues second emergency patch for CVE-2026-82078 and CVE-2026-81578

    Mitigation Patch Update

    PaperCut publicly disclosed CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and PaperCut MF, said the fresh emergency fix adds additional hardening beyond the original emergency patch, and urged organizations to remove public exposure, restrict PaperCut Application Server web access to trusted IP addresses or a VPN, and apply the patch immediately.

    Show sources