PaperCut released a second emergency patch for CVE-2026-81578 and CVE-2026-82078, two actively exploited zero-days that can be chained for pre-authentication remote code execution on Internet-exposed PaperCut NG and PaperCut MF servers. The release followed reports that attackers could bypass the initial fix; Huntress observed intrusions on 26 and 27 August in which threat actors rapidly deployed hex-encoded Java class files and conducted host reconnaissance. Supported PaperCut versions 24 through 26 have updates, while version 23 and earlier require a full upgrade.
Basel-Stadt schools detected unauthorized attempts to access their printing system during the night of 3 September despite having promptly applied vendor updates for the late-August vulnerability. The Education Department disconnected the system as a precaution, disrupting printing for about one school day; limited service resumed Friday, while broader restoration was planned for 7 September. Authorities reported no evidence of data theft, notified relevant cantonal bodies, opened an independent investigation and filed a criminal complaint; rather than restore the prior environment, they will fully rebuild it to reduce the risk of undetected malware.

See which actors are running it and whether you're in range.
18 events from the most recent confirmed update back to the earliest known activity.
Blackpoint Cyber’s Adversary Pursuit Group published an analysis of infrastructure at 45.142.193.132 that allegedly exposed an AI-assisted PaperCut exploitation project. The recovered materials described a 4,107-IP target list, 517 targets processed by September 1, multithreaded Go exploitation and retry tooling, and post-exploitation capabilities including administrator-account creation, Active Directory discovery, SOCKS proxying, and LSA-secret collection.
Limited printing capability became available again following the network isolation, while some day-structure facilities remained subject to restrictions.
During the night, Basel schools detected unauthorized access attempts through their printing system despite having installed the vendor's updates. The Education Department immediately disconnected the system from the network, interrupting printing for about one school day.
GreyNoise assessed that a likely Russian-speaking actor began using AI-assisted workflows to exploit CVE-2026-81578 and CVE-2026-82078 on August 31, compromising at least 440 PaperCut NG/MF instances at 395 organizations in 48 countries. The campaign heavily affected education organizations and, in some cases, achieved domain administrator access and used DCSync to obtain NTDS.DIT credential data.
CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities Catalog after PaperCut disclosed active exploitation of the chained flaws.
PaperCut issued emergency patches for CVE-2026-81578 and CVE-2026-82078 after confirming customer incidents involving the actively exploited PaperCut MF/NG vulnerabilities. These emergency fixes preceded the later second emergency patch release documented in the existing timeline.
Huntress documented exploitation in a second customer environment. One observed complete intrusion took less than two minutes and did not include ransomware or an additional payload.
Huntress documented an intrusion exploiting the PaperCut flaws in a customer environment; attackers deployed hex-encoded Java class files and conducted basic host reconnaissance.
PaperCut issued Emergency Patch Release 2 for actively exploited CVE-2026-81578 and CVE-2026-82078 after watchTowr and Huntress identified bypasses of the initial patch. The chained flaws enable pre-authentication remote code execution on exposed PaperCut NG and MF servers; the release supports versions 24 through 26, while older versions require a full upgrade.
Basel's Education Department promptly installed the security updates supplied by its printing-software manufacturer following the vulnerability disclosure.
The manufacturer of printing software used by Basel schools disclosed a security vulnerability in late August 2026.
GreyNoise reportedly observed IP address 45.142.193.132 probing internet-facing Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE systems beginning in early July 2026, before the infrastructure pivoted to PaperCut exploitation.
GreyNoise reported that the AI-assisted PaperCut campaign harvested credentials from 280 compromised hosts and exfiltrated secrets from 137. It identified post-exploitation paths involving LSASS-memory and registry-secret collection, NoPac attacks against unpatched systems, and adding accounts to Domain Admins on compromised domain controllers.
PaperCut released PaperCut NG/MF maintenance versions 26.0.5, 25.0.13, and 24.1.10, replacing prior emergency-patch builds for actively exploited CVE-2026-81578 and CVE-2026-82078. The releases incorporate fixes from Emergency Patch Releases 1 through 3, address two regressions, and add security hardening and attack-chain mitigations.
A report claimed that Claude Opus analyzed a patch for an unspecified PaperCut NG zero-day, identified three critical vulnerabilities, and created a proof-of-concept exploit chain achieving unauthenticated code execution. The report did not identify CVEs, affected versions, or provide technical validation details.
Arctic Wolf documented infrastructure, payload hashes, command lines, server-log artifacts, and file indicators associated with exploitation of CVE-2026-81578 and CVE-2026-82078. The report identified credential-harvesting tools, Meterpreter-related payload infrastructure, and indicators for defenders to hunt on PaperCut servers.
Arctic Wolf observed attackers exploiting chained PaperCut CVE-2026-81578 and CVE-2026-82078 against K-12 schools and universities in the United States and Europe. The intruders performed reconnaissance, created an "Administrator17" privileged account, collected registry hives and PaperCut configuration data, and retrieved Meterpreter-related payloads.
Basel reported the printing-system incident to responsible cantonal bodies, engaged independent external security experts, and filed a criminal complaint. Investigators had no indication of data exfiltration, and the Education Department decided to fully rebuild rather than restore the prior printing system.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
22 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemkd-cirt.mk
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcegithub.com
Open sourcecyberveille.ch
Open sourcecirt.cm
Open sourceblackpointcyber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.