HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

AI Agents Exploit PaperCut NG/MF Vulnerabilities (CVE‑2026‑81578, CVE‑2026‑82078) to Breach 395 Organizations

A Russian‑speaking threat actor built exploits for two PaperCut NG/MF flaws and used AI agents to automate attacks, compromising 395 organizations in 48 countries. The incident underscores the importance of continuous vulnerability management and auditable patch‑deployment evidence for compliance readiness.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

AI Agents Exploit PaperCut NG/MF Vulnerabilities (CVE‑2026‑81578, CVE‑2026‑82078) to Breach 395 Organizations

What Happened — Threat actors built an exploit for two newly disclosed PaperCut NG/MF flaws (CVE‑2026‑81578, CVE‑2026‑82078) and handed the exploitation workflow to AI agents. The agents automated scanning, exploitation, and credential harvesting, compromising at least 440 PaperCut instances across 395 organizations in 48 countries, with many victims gaining domain‑admin rights within minutes.

Why It Matters for Trust & Control Assurance

  • Highlights the risk of relying on manual patch‑management processes; continuous vulnerability monitoring is essential to prove due diligence.
  • Demonstrates the need for auditable evidence that critical patches are applied promptly and that external access to management interfaces is restricted.
  • Shows how a single unpatched component can break multiple control objectives (vulnerability management, access control, supply‑chain oversight) across frameworks.

Who Is Affected – Primarily the education sector (204 of 395 victims), but also healthcare, government, and private enterprises using PaperCut for print management.

Recommended Actions

  1. Inventory all PaperCut deployments and verify they run the latest patched version.
  2. Apply the emergency patches released in August 2026 and immediately block public‑internet access to the PaperCut Application Server.
  3. Integrate automated vulnerability scanning for third‑party software into your continuous control‑assurance platform and retain evidence of remediation for audit purposes.

Technical Notes – The exploited flaws allowed remote code execution and privilege escalation to domain‑admin rights. Attackers used OpenAI Codex and a DeepSeek model to orchestrate the campaign, leveraging Netlas.io for target discovery. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/11/ai-agents-papercut-ng-mf-attack-campaign/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →