AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally

AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally

First seen 9 Sep 2026, 18:13 UTC GreynoiseCybersecuritynews 78.7

Article Content

Browse articles
ThreatCluster

A Russian-speaking threat actor has launched a global campaign utilizing artificial intelligence to exploit critical vulnerabilities in PaperCut NG/MF software, compromising at least 440 servers across 395 organizations in 48 countries. The campaign, identified by GreyNoise, involved the use of AI agents to achieve remote code execution (RCE) and credential harvesting through vulnerabilities CVE-2026-81578 and CVE-2026-82078. The adversary developed exploits in a lab environment and used tools like OpenAI's Codex and DeepSeek model. The attack was rapid, with the adversary achieving domain administrator access within minutes in some cases. Despite attempts to avoid certain countries, the campaign's scope was extensive, indicating a high level of automation and sophistication in the attack methodology. The vulnerabilities were added to CISA's KEV list on August 31, 2026, shortly after their public disclosure on August 28, 2026. Organizations are urged to assess their PaperCut installations for these vulnerabilities.

Key Points: • AI agents were used to exploit PaperCut vulnerabilities, compromising 440 servers. • The campaign targeted CVE-2026-81578 and CVE-2026-82078, added to CISA KEV list on August 31. • Rapid exploitation allowed domain admin access within minutes for some victims.

Ask AI about this cluster

Timeline

2021-11-10
CVE-2021-42287 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-11-10
CVE-2021-42278 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-28
CVE-2026-81578 and CVE-2026-82078 published
Critical vulnerabilities in PaperCut NG/MF software disclosed, enabling remote code execution.
Greynoise
2026-08-31
CVE vulnerabilities added to CISA KEV
CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog.
Greynoise
2026-09-09
Global campaign identified by GreyNoise
GreyNoise reported that a Russian-speaking actor used AI to compromise 440 PaperCut instances worldwide.
Cybersecuritynews