Greynoise
AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally
Article Content
A Russian-speaking threat actor has launched a global campaign utilizing artificial intelligence to exploit critical vulnerabilities in PaperCut NG/MF software, compromising at least 440 servers across 395 organizations in 48 countries. The campaign, identified by GreyNoise, involved the use of AI agents to achieve remote code execution (RCE) and credential harvesting through vulnerabilities CVE-2026-81578 and CVE-2026-82078. The adversary developed exploits in a lab environment and used tools like OpenAI's Codex and DeepSeek model. The attack was rapid, with the adversary achieving domain administrator access within minutes in some cases. Despite attempts to avoid certain countries, the campaign's scope was extensive, indicating a high level of automation and sophistication in the attack methodology. The vulnerabilities were added to CISA's KEV list on August 31, 2026, shortly after their public disclosure on August 28, 2026. Organizations are urged to assess their PaperCut installations for these vulnerabilities.
Key Points: • AI agents were used to exploit PaperCut vulnerabilities, compromising 440 servers. • The campaign targeted CVE-2026-81578 and CVE-2026-82078, added to CISA KEV list on August 31. • Rapid exploitation allowed domain admin access within minutes for some victims.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.