AI-Powered Attacks Exploit Unpatched PaperCut Vulnerabilities at Scale
A suspected Russian-speaking threat actor exploited two newly disclosed vulnerabilities in PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078), compromising over 440 instances — many in the education sector — before patches could be widely applied. The use of hundreds of AI agents allowed the attacker to dramatically accelerate exploitation at a scale and speed that traditional manual attacks could not match, moving from initial access to domain administrator privileges with alarming efficiency. This incident illustrates that the window between vulnerability disclosure and active exploitation is shrinking to near-zero, especially when adversaries leverage AI to automate offensive operations. Organizations that lack rapid patch deployment processes and compensating controls are increasingly exposed in this new threat landscape.
Tactical Insight
Immediate actions
- Apply vendor-released patches for CVE-2026-81578 and CVE-2026-82078 to all PaperCut NG/MF instances without delay.
- Isolate or take offline any unpatched PaperCut instances that are internet-facing until remediation is complete.
- Audit all PaperCut administrator and service accounts for signs of unauthorized access or privilege escalation.
Detection measures
- Deploy behavioral monitoring to detect anomalous activity on print management servers, including unusual admin logins or lateral movement patterns.
- Enable and centralize logging for PaperCut application events and correlate them with SIEM alerts for rapid triage.
- Implement threat intelligence feeds that flag AI-assisted attack patterns and indicators of compromise associated with this campaign.
Long-term improvements
- Establish a formal emergency patching SLA (e.g., 24–72 hours) for critical vulnerabilities in internet-facing systems.
- Apply network segmentation to isolate print management infrastructure from core domain controllers and sensitive networks.
- Enforce least-privilege access principles on all print management accounts to limit the blast radius of any future compromise.