Threat Intelligence

PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws

The Hacker News · 11 Sept 2026
Key Takeaway If your business uses PaperCut print management software, update immediately to the latest maintenance release, don't rely on older emergency patches, as attackers are actively exploiting these flaws using automated tools.

PaperCut has released new maintenance versions of its NG/MF software (26.0.5, 25.0.13 and 24.1.10) that replace the three emergency patches issued earlier to fix two security flaws under active attack. Unlike the rushed emergency releases, these versions have been through PaperCut's full quality assurance process and include additional security hardening, along with fixes for regressions caused by the earlier patches.

The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, allow attackers to bypass authentication and run arbitrary code on vulnerable PaperCut systems. Security researchers at GreyNoise and Blackpoint Cyber have linked exploitation of these flaws to a suspected Russian-speaking threat actor who has already breached at least 395 organisations across 48 countries, with a heavy concentration in the US education sector. The attacker reportedly used hundreds of AI agents built on OpenAI's Codex and a DeepSeek model to scale their attacks automatically, deliberately avoiding targets in Russia, China and roughly two dozen other countries.

It is not yet clear whether the attacker intends to sell access to other criminal groups or use it directly for data theft or ransomware. Given the scale and automation involved, organisations running PaperCut should treat this as an urgent priority.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.