Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

PaperCut Issues Stable Fix as AI-Powered Attacks Widen

PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

PaperCut Issues Stable Fix as AI-Powered Attacks Widen
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

PaperCut released a Security Maintenance Release (SMR) for NG and MF that replaces every emergency patch issued since CVE-2026-81578 and CVE-2026-82078 were disclosed, per The Hacker News. If you applied Emergency Patch Release 1 or 2, the SMR supersedes your current fix.

SecurityWeek reports that a Russian threat actor is using AI tooling to build, test, and deploy exploits against these same PaperCut flaws across hundreds of organizations worldwide. The SMR is PaperCut’s response to a bypass cycle that already outlasted two emergency fixes.

The vulnerabilities

CVE-2026-81578 is the auth bypass, CVSS 9.8. Malformed requests reach backend administrative functions before access validation runs, bypassing the login requirement without credentials.

CVE-2026-82078 is the RCE, CVSS 9.1. An attacker past the auth bypass can reconfigure external database settings to load arbitrary Java classes, achieving code execution on the print server.

Both are on CISA’s Known Exploited Vulnerabilities list with a September 14 federal remediation deadline. The SMR is the fix that satisfies that deadline. Emergency patches do not.

AI-assisted exploitation

SecurityWeek’s reporting identifies a Russian threat actor compressing the build-test-deploy cycle for PaperCut exploits using AI tooling. The target list runs into the hundreds of organizations worldwide.

Earlier attack waves hit education and enterprise environments. Credential theft at schools and the CISA KEV addition at the start of September confirmed sustained targeting. The AI component in the current campaign is what SecurityWeek’s reporting adds; prior incidents documented manual exploitation chains.

Analysis: an adversary iterating exploits with AI tooling is harder to outrun with incremental emergency patches. A Security Maintenance Release addresses more surface area than targeted hotfixes. Organizations that applied EP2 still need to move to the SMR.

Patch

Apply the Security Maintenance Release. PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS are covered. Patch downloads and version-specific upgrade paths are in PaperCut’s security bulletin.

PaperCut 23 and older are out of support. Upgrade to a current release before applying the SMR.

Temporary measure if patching is not immediate: restrict the PaperCut web management interface to trusted internal IP ranges via firewall rules. This narrows the attack surface. It does not close the vulnerability.


Prior coverage:

Related CVEs

Found this useful? Share it.