PaperCut disclosed active exploitation of PaperCut NG/MF servers on August 27 with no CVE, no available exploit sample, and no patch. An emergency fix issued the next day was bypassed within hours, and a third patch only arrived on September 1, leaving customers exposed for roughly six days while attackers were already using the flaw in live attacks. A security researcher uses the episode to argue that the industry's old assumptions about response timelines no longer hold.
bleepingcomputer.com
· 2026-09-15
GreyNoise reports that a suspected Russian-speaking threat actor deployed hundreds of AI agents, trained in a lab, to hunt down internet-exposed PaperCut NG and MF servers and exploit two known vulnerabilities. The campaign hit at least 440 instances across 395 organizations in 48 countries, with attackers pivoting from initial compromise toward Windows Active Directory environments.
darkreading.com
· 2026-09-11
GreyNoise reports that a likely Russian-speaking threat actor deployed hundreds of AI agents using OpenAI's Codex and DeepSeek models to build and launch exploits against two PaperCut NG/MF vulnerabilities. The campaign, which began August 31, compromised at least 440 servers across 395 organizations in 48 countries, mostly in education, with credentials stolen from 280 victims and admin access gained at 12 organizations.
bleepingcomputer.com
· 2026-09-10
Hackers are actively exploiting two recently disclosed PaperCut NG and MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and steal data from print management servers. PaperCut issued emergency fixes last week, but researchers at Defused say attackers are using the bypass to hijack the software's user-lookup function and dump database tables rather than pursue remote code execution as earlier reports suggested. Over 800 PaperCut servers remain exposed online according to Shadowserver, and PaperCut has not yet attributed the attacks or detailed post-compromise activity.
bleepingcomputer.com
· 2026-09-01
PaperCut released a follow-up emergency update for PaperCut NG and MF after researchers found ways around its initial patch for actively exploited vulnerabilities. The company disclosed CVE-2026-82078, a critical unsafe dynamic class-loading bug, and CVE-2026-81578, a high-severity authentication bypass, which can be chained to let unauthenticated attackers execute code on vulnerable servers.
bleepingcomputer.com
· 2026-08-28
PaperCut has disclosed that hackers are actively exploiting an unpatched vulnerability affecting every version of its PaperCut NG and PaperCut MF print management software. The company confirmed real customer incidents, discovered the flaw after reproducing it with data from an affected university, and has since issued emergency patches for internet-facing servers.
bleepingcomputer.com
· 2026-08-27