AI-Orchestrated Exploitation of PaperCut RCE Vulnerability Chain
Score: 8/10

AI-Orchestrated Exploitation of PaperCut RCE Vulnerability Chain

A suspected Russian-speaking threat actor is using AI-powered agents to exploit a critical PaperCut NG/MF vulnerability chain (CVE-2026-81578 and CVE-2026-82078) to target the education sector globally.

Executive Summary

A sophisticated campaign attributed to a suspected Russian-speaking threat actor has targeted over 395 organizations across 48 countries, primarily within the U.S. and European education sectors. The actor leverages a critical vulnerability chain in PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078) to bypass authentication and achieve remote code execution. The campaign is notable for its use of hundreds of AI agents powered by OpenAI Codex and DeepSeek models to automate vulnerability research, target identification, and exploit troubleshooting, significantly reducing the human effort required for large-scale compromise.

The attack chain involves initial reconnaissance via Netlas.io followed by the deployment of offensive tools like Metasploit, Mimikatz, and Rubeus. Once access is achieved, the actor focuses on credential harvesting and establishing persistence, often reaching domain administrator status within minutes of initial entry. While the final objectives remain unconfirmed, the methodology is highly consistent with initial access brokers seeking to hand off environments to ransomware affiliates like Lace Tempest (Cl0p/LockBit).

Immediate action is required for organizations running PaperCut NG/MF. PaperCut has released maintenance versions (26.0.5, 25.0.13, 24.1.10) that supersede previous emergency patches. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities catalog, highlighting the urgency of remediation.

Key Details

Threat Name

CVE-2026-81578 and CVE-2026-82078

Affects

PaperCut NG, PaperCut MF, PaperCut servers

Adversary

suspected Russian-speaking threat actor Other Adversaries and Aliases: MCA; initial access brokers; Lace Tempest

Malware/Tools

Metasploit, Mimikatz, SharpHound, Certipy, Rubeus, Impacket, SimpleHelp, Cl0p, LockBit, Meterpreter, lsa_collect.exe, save_hives.exe

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth8

Sources