Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 53
2 unique sources, 4 articles

Summary

Hide ▲

PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously reported compromise activity against K-12 schools and major universities in the U.S. and Europe, with post-exploitation including command execution, reconnaissance, privileged account creation, and registry hive collection. New reporting from GreyNoise and Blackpoint Cyber says the campaign began August 31 and used hundreds of AI agents with OpenAI Codex, DeepSeek, and Netlas to build and refine exploits before launching at scale. GreyNoise attributed at least 440 PaperCut instances across 395 organizations in 48 countries to the activity, with 280 victims losing credentials and 12 organizations reaching administrator access.

Related Happenings

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...

Red Heron Gitea CVE-2026-60004 exploitation wave

Exploitation Wave
H score22 First: 14.09.2026 19:56 Last: 14.09.2026 19:56 Sources 1

About this happening: An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...

JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave

Exploitation Wave
H score56 First: 11.09.2026 19:29 Last: 11.09.2026 19:29 Sources 1

About this happening: JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave
H score55 First: 01.09.2026 20:53 Last: 01.09.2026 20:53 Sources 1

About this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability
H score53 First: 28.08.2026 20:12 Last: 28.08.2026 20:12 Sources 1

How related: The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances.

About this happening: PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...

Latest development: 10.09.2026 14:41

A suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

Timeline

  1. 05.09.2026 10:31 5 articles · 13d ago

    Active PaperCut exploitation targets schools and universities

    Exploitation Observed

    Arctic Wolf said attackers were actively exploiting CVE-2026-81578 and CVE-2026-82078 in vulnerable PaperCut servers used by K-12 schools and major universities in the U.S. and Europe, with post-exploitation activity including command execution, reconnaissance, privileged account creation, registry hive collection, Meterpreter-related Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.

    Show sources