PaperCut patched in one day. Attackers had already breached 395 organisations.
SecurityWeek reports that threat intelligence firm GreyNoise counted 440 compromised PaperCut NG/MF print-management deployments across 395 organisations in 48 countries.
The vulnerabilities, CVE-2026-82078 and CVE-2026-81578, were disclosed as zero-days on 27 August and patched by PaperCut on 28 August. They let a remote unauthenticated attacker bypass authentication, then run code.
GreyNoise attributes the campaign to a Russian-speaking threat actor and says the attacker "used AI to build, test, and deploy exploits". Some environments were compromised "in minutes and even seconds".
The firm found credential-harvesting attempts on 280 hosts, with secrets taken from 137. Attackers obtained domain administrator privileges at 12 organisations.
Education accounted for 204 compromised deployments. Retail and manufacturing were among the other sectors affected.
Which system in your estate would take you more than a day to patch?
Sources
For your next steering committee
- 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
- 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
- 3Ask how long a restore took the last time it was tested.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01
