PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously reported compromise activity against K-12 schools and major universities in the U.S. and Europe, with post-exploitation including command execution, reconnaissance, privileged account creation, and registry hive collection. New reporting from GreyNoise and Blackpoint Cyber says the campaign began August 31 and used hundreds of AI agents with OpenAI Codex, DeepSeek, and Netlas to build and refine exploits before launching at scale. GreyNoise attributed at least 440 PaperCut instances across 395 organizations in 48 countries to the activity, with 280 victims losing credentials and 12 organizations reaching administrator access.
Related Happenings
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation Wave
H score16
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation Wave
H score22
First: 14.09.2026 19:56
Last: 14.09.2026 19:56
Sources 1
About this happening:
An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
Red Heron Gitea CVE-2026-60004 exploitation wave
Exploitation WaveAbout this happening: An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning fram...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation Wave
H score56
First: 11.09.2026 19:29
Last: 11.09.2026 19:29
Sources 1
About this happening:
JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
JFrog Artifactory CVE-2026-42018/CVE-2026-42016 exploitation wave
Exploitation WaveAbout this happening: JFrog Artifactory is in an active exploitation wave involving CVE-2026-42018 and CVE-2026-42016, where attackers used the flaws to move from low-privilege access t...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score55
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
H score53
First: 28.08.2026 20:12
Last: 28.08.2026 20:12
Sources 1
How related:
The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances.
About this happening:
PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
VulnerabilityHow related: The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances.
About this happening: PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...
Latest development: 10.09.2026 14:41
A suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
Timeline
-
05.09.2026 10:31 5 articles · 13d ago
Active PaperCut exploitation targets schools and universities
Exploitation ObservedArctic Wolf said attackers were actively exploiting CVE-2026-81578 and CVE-2026-82078 in vulnerable PaperCut servers used by K-12 schools and major universities in the U.S. and Europe, with post-exploitation activity including command execution, reconnaissance, privileged account creation, registry hive collection, Meterpreter-related Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.
Show sources
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — thehackernews.com — 05.09.2026 10:31
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — thehackernews.com — 05.09.2026 10:31
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — thehackernews.com — 10.09.2026 14:41
- AI-powered attack exploited PaperCut flaws to hack 395 organizations — www.bleepingcomputer.com — 10.09.2026 18:55
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws — thehackernews.com — 11.09.2026 09:46