Organizations relying on PaperCut print management software must immediately replace temporary emergency fixes with newly finalized maintenance releases following ongoing, automated exploitation of two critical vulnerabilities. The flaws—tracked as CVE-2026-81578 and CVE-2026-82078—allow unauthenticated attackers to bypass authentication controls and execute arbitrary code on vulnerable servers. While PaperCut initially deployed Emergency Patch Releases 1, 2, and 3 to slow down in-the-wild attacks, those interim builds introduced functional regressions and partial mitigations.
PaperCut has now issued full Regular Maintenance Releases (MR) that have completed standard quality assurance testing. The newly updated, supported versions—PaperCut NG/MF 26.0.5, 25.0.13, and 24.1.10—roll up all interim security hotfixes, resolve the software regressions, and apply additional defense-in-depth security hardening against multi-stage attack chains.
Automated Exploitation via AI Agent Tooling
Threat intelligence from GreyNoise and Blackpoint Cyber confirms active, widespread weaponization of both CVE-2026-81578 and CVE-2026-82078 by a suspected Russian-speaking threat actor. The campaign has compromised at least 395 organizations across 48 countries, with attacks heavily concentrated against the U.S. education sector.
What distinguishes this campaign is the threat actor’s use of artificial intelligence to automate initial access at scale. The adversary deployed hundreds of autonomous AI agents managed through OpenAI’s Codex harness and an integrated DeepSeek model. This automated framework scans, parses, and executes multi-step exploit payloads against vulnerable PaperCut instances dynamically, adjusting to server responses without manual human intervention.
The attack infrastructure includes embedded target-exclusion rules designed to avoid specific geopolitical regions. The automated exploit scripts explicitly bypass systems located in Russia, China, Hong Kong, Thailand, Iran, and 23 other nations. Threat intelligence telemetry indicates that malicious scanning and exploitation traffic originates from the primary IP address 45.142.193[.]132. Researchers note it remains unclear whether the actor intends to conduct follow-on operations directly—such as enterprise ransomware deployment or data theft—or sell the established footholds to secondary cybercrime affiliates.
Vulnerability Mechanics and Enterprise Blast Radius
The pairing of an authentication bypass with unauthenticated remote code execution (RCE) makes any PaperCut vulnerability extremely high-risk. In enterprise and higher education environments, PaperCut NG and MF operate as central print management servers, typically installed with elevated system privileges—such as NT AUTHORITY\SYSTEM on Windows hosts or root on Linux deployments.
Because print infrastructure requires deep integration with corporate directory services (such as Active Directory or LDAP) for user routing and quota management, a compromise of the PaperCut application server yields significant operational control:
- Complete Local System Takeover: Achieving unauthenticated RCE at the
SYSTEMlevel allows attackers to dump local credentials, terminate local Endpoint Detection and Response (EDR) agents, and establish persistent web shells or reverse proxy tunnels into internal subnets. - Domain Privilege Escalation: Print servers routinely store high-privileged service accounts. Attackers gaining an initial foothold on the PaperCut server can extract cached Kerberos tickets or cleartext service passwords to escalate privileges across the Active Directory domain.
- Broad Surface Exposure: Educational institutions frequently expose PaperCut web portals (typically running on ports 9191 and 9192) to untrusted campus networks or the public internet to facilitate student and guest printing, increasing the attack surface accessible to external scanners.
Furthermore, temporary mitigations and interim emergency patches introduced operational regressions in some print environments, leading some administrators to delay deployment or leave mitigations partially applied—creating an ideal environment for automated AI scanners to find unpatched endpoints.
Required Actions and Detection Guidance
Given that interim emergency patches have been superseded and actively exploited attack chains exist in the wild, administrators should prioritize updating all print servers immediately.
- Deploy Maintenance Releases: Upgrade all PaperCut NG and PaperCut MF instances to version 26.0.5, 25.0.13, or 24.1.10 depending on your major version train. If your organization is running Emergency Patch Release 1, 2, or 3, you must upgrade to these official maintenance releases to ensure full coverage against regression issues and exploit variants.
- Restrict Management Interfaces: Ensure management ports (9191/9192) are blocked at the perimeter firewall and removed from public internet exposure. Access to PaperCut admin interfaces should require an authenticated VPN connection or Zero Trust Network Access (ZTNA) control.
- Monitor Indicators of Compromise: Query perimeter firewalls, web proxies, and SIEM logs for any inbound connection attempts or payload delivery originating from
45.142.193[.]132. - Audit Process Execution Logs: Inspect endpoint detection logs on PaperCut host servers for abnormal child processes spawned by the PaperCut service executable (such as
cmd.exe,powershell.exe,bash, orsh), which indicates potential command injection post-exploitation.
Related content
PaperCut Zero-Days Exploited in Active Data Theft Attacks
Security NewsAttackers Target Education Sector via PaperCut Vulnerabilities CVE-2026-81578 and…
AdvisoryPaperCut NG/MF Critical Vulnerability CVE-2026-81578 Exposes Systems to Takeover
AdvisoryPaperCut NG/MF Unsafe Reflection Vulnerability (CVE-2026-82078) Analysis
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call