<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

AI Agents Breached 395 Organizations via PaperCut Zero-Days

A single attacker compromised 440 PaperCut deployments across 48 countries, hours after turning two freshly disclosed flaws into working exploits.
Content Team

A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.

Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.

PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo