PaperCut Issues Stable Fix as AI-Powered Attacks Widen
PaperCut's SMR replaces all emergency patches for CVE-2026-81578 and CVE-2026-82078. AI-assisted attacks are active against hundreds of organizations.

PaperCut released a Security Maintenance Release (SMR) for NG and MF that replaces every emergency patch issued since CVE-2026-81578 and CVE-2026-82078 were disclosed, per The Hacker News. If you applied Emergency Patch Release 1 or 2, the SMR supersedes your current fix.
SecurityWeek reports that a Russian threat actor is using AI tooling to build, test, and deploy exploits against these same PaperCut flaws across hundreds of organizations worldwide. The SMR is PaperCut’s response to a bypass cycle that already outlasted two emergency fixes.
The vulnerabilities
CVE-2026-81578 is the auth bypass, CVSS 9.8. Malformed requests reach backend administrative functions before access validation runs, bypassing the login requirement without credentials.
CVE-2026-82078 is the RCE, CVSS 9.1. An attacker past the auth bypass can reconfigure external database settings to load arbitrary Java classes, achieving code execution on the print server.
Both are on CISA’s Known Exploited Vulnerabilities list with a September 14 federal remediation deadline. The SMR is the fix that satisfies that deadline. Emergency patches do not.
AI-assisted exploitation
SecurityWeek’s reporting identifies a Russian threat actor compressing the build-test-deploy cycle for PaperCut exploits using AI tooling. The target list runs into the hundreds of organizations worldwide.
Earlier attack waves hit education and enterprise environments. Credential theft at schools and the CISA KEV addition at the start of September confirmed sustained targeting. The AI component in the current campaign is what SecurityWeek’s reporting adds; prior incidents documented manual exploitation chains.
Analysis: an adversary iterating exploits with AI tooling is harder to outrun with incremental emergency patches. A Security Maintenance Release addresses more surface area than targeted hotfixes. Organizations that applied EP2 still need to move to the SMR.
Patch
Apply the Security Maintenance Release. PaperCut NG and MF versions 24, 25, and 26 on Windows, Linux, and macOS are covered. Patch downloads and version-specific upgrade paths are in PaperCut’s security bulletin.
PaperCut 23 and older are out of support. Upgrade to a current release before applying the SMR.
Temporary measure if patching is not immediate: restrict the PaperCut web management interface to trusted internal IP ranges via firewall rules. This narrows the attack surface. It does not close the vulnerability.
Prior coverage:
- PaperCut Issues Second Patch as Bypasses Found (August 29)
- PaperCut Active Intrusions: CISA Adds Flaws to KEV (September 1)
- PaperCut Attackers Steal Credentials From Schools (September 5)
- [ CRITICAL ]CVE-2026-81578PaperCut NG/MF Authentication Bypass
- [ CRITICAL ]CVE-2026-82078PaperCut NG/MF Unsafe Class-Loading RCE
Found this useful? Share it.


