PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution chain affecting exposed instances. PaperCut issued a second emergency patch and told operators to remove public internet exposure and restrict PaperCut Application Server access to trusted IPs or a VPN. The latest reporting says a suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits, then compromised at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland. Earlier observed post-exploitation activity included a Java `.class` file, Base64-encoded commands, and commands such as `whoami & ver & tasklist` on a PaperCut target.
Related Happenings
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
H score42
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
About this happening:
Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and depl...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation WaveAbout this happening: Multiple threat actors are actively exploiting JFrog Artifactory through CVE-2026-42018 and CVE-2026-42016 to bypass authentication, mint admin-scoped tokens, and depl...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
How related:
At its core, the opportunistic attacks exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, to mainly target the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveHow related: At its core, the opportunistic attacks exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, to mainly target the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentHow related: Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims' servers.
About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
PaperCut NG and MF actively exploited zero-day security flaw
Vulnerability
H score53
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...
PaperCut NG and MF actively exploited zero-day security flaw
VulnerabilityAbout this happening: PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise r...
Timeline
-
10.09.2026 14:41 2 articles · 1d ago
Suspected Russian-speaking actor compromises 440 PaperCut instances with AI agents
Campaign Scope UpdateA suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
Show sources
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — thehackernews.com — 10.09.2026 14:41
- AI-powered attack exploited PaperCut flaws to hack 395 organizations — www.bleepingcomputer.com — 10.09.2026 18:55
-
28.08.2026 20:12 3 articles · 13d ago
Attackers run whoami, ver, and tasklist on a PaperCut server
Exploitation ObservedIn an incident recorded on August 27, 2026, threat actors used a different Java `.class` file against a PaperCut target to run `whoami & ver & tasklist`, showing post-exploitation activity after limited exploitation in customer environments.
Show sources
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- Recently patched PaperCut zero-days used in data theft attacks — www.bleepingcomputer.com — 01.09.2026 10:48
-
28.08.2026 20:12 3 articles · 13d ago
PaperCut issues second emergency patch for CVE-2026-82078 and CVE-2026-81578
Mitigation Patch UpdatePaperCut publicly disclosed CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and PaperCut MF, said the fresh emergency fix adds additional hardening beyond the original emergency patch, and urged organizations to remove public exposure, restrict PaperCut Application Server web access to trusted IP addresses or a VPN, and apply the patch immediately.
Show sources
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- PaperCut releases second emergency patch for exploited flaws — www.bleepingcomputer.com — 28.08.2026 22:08
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws — thehackernews.com — 11.09.2026 09:46