Back to Blog
CVE-2026-81578, CVE-2026-82078: PaperCut NG/MF — AI-Driven Mass Compromise (September 2026)
vulnerabilities

CVE-2026-81578, CVE-2026-82078: PaperCut NG/MF — AI-Driven Mass Compromise (September 2026)

breachwire TeamSep 12, 20262 min read

CVE-2026-81578, CVE-2026-82078 — PaperCut NG/MF

CVE-2026-81578 and CVE-2026-82078 are critical vulnerabilities in PaperCut NG/MF, currently exploited in the wild by a Russian-speaking threat actor leveraging AI agents. These flaws enable attackers to automate initial access, escalate privileges, and extract credentials, with full domain compromise achieved in minutes. No official CVSS score is published, but observed impact is severe and widespread.

Attack Vector

Attackers deploy AI agents to scan for exposed PaperCut NG/MF instances, exploiting CVE-2026-81578 and CVE-2026-82078 to bypass authentication and execute arbitrary code. The automation enables rapid chaining of exploits: initial access is followed by credential harvesting, OS/domain secret extraction, and privilege escalation to domain admin. In 440 confirmed cases, attackers moved from access to full compromise in under five minutes. Indicators of compromise include anomalous PaperCut process activity, unexpected outbound connections, and rapid privilege escalation events.

Who Is at Risk

All organizations running unpatched PaperCut NG/MF are vulnerable, regardless of deployment size. The attack has breached 395 organizations across 48 countries, with education sector entities in the US and Europe most affected. Confirmed impacts include credential theft (280 victims), domain/OS secret extraction (147), and domain admin takeover (12 organizations). Any externally accessible PaperCut instance is at immediate risk.

Patch & Mitigate

  • Patch: Apply the latest PaperCut NG/MF security updates released September 2026. Patch all internet-facing and internal instances without delay.
  • Workaround: If patching is not immediately possible, restrict network access to PaperCut servers and disable unnecessary external exposure.
  • Detect: Review logs for unauthorized logins, privilege escalations, and suspicious process launches from PaperCut services. Monitor for outbound traffic to unfamiliar destinations.

MITRE ATT&CK

  • TA0007 — Discovery: Attackers enumerate environment and credentials post-exploitation.
  • TA0008 — Lateral Movement: Exploited credentials and secrets enable rapid movement to domain admin.
  • TA0006 — Credential Access: Automated tools extract credentials and secrets from compromised systems.

Source: https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: