AI Agents Exploit PaperCut NG/MF Vulnerabilities (CVE‑2026‑81578, CVE‑2026‑82078) to Breach 395 Organizations
What Happened — Threat actors built an exploit for two newly disclosed PaperCut NG/MF flaws (CVE‑2026‑81578, CVE‑2026‑82078) and handed the exploitation workflow to AI agents. The agents automated scanning, exploitation, and credential harvesting, compromising at least 440 PaperCut instances across 395 organizations in 48 countries, with many victims gaining domain‑admin rights within minutes.
Why It Matters for Trust & Control Assurance
- Highlights the risk of relying on manual patch‑management processes; continuous vulnerability monitoring is essential to prove due diligence.
- Demonstrates the need for auditable evidence that critical patches are applied promptly and that external access to management interfaces is restricted.
- Shows how a single unpatched component can break multiple control objectives (vulnerability management, access control, supply‑chain oversight) across frameworks.
Who Is Affected – Primarily the education sector (204 of 395 victims), but also healthcare, government, and private enterprises using PaperCut for print management.
Recommended Actions –
- Inventory all PaperCut deployments and verify they run the latest patched version.
- Apply the emergency patches released in August 2026 and immediately block public‑internet access to the PaperCut Application Server.
- Integrate automated vulnerability scanning for third‑party software into your continuous control‑assurance platform and retain evidence of remediation for audit purposes.
Technical Notes – The exploited flaws allowed remote code execution and privilege escalation to domain‑admin rights. Attackers used OpenAI Codex and a DeepSeek model to orchestrate the campaign, leveraging Netlas.io for target discovery. Source: Help Net Security