INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

PaperCut Fixes Two Actively Exploited Flaws

| 2026-09-11 07:56 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On September 11, 2026, a suspected Russian-speaking threat actor was found to be weaponizing two actively exploited flaws in PaperCut's software, CVE-2026-81578 and CVE-2026-82078, to break into at least 395 organizations across 48 countries, with the majority concentrated in the U.S. education sector. The attacks utilized hundreds of AI agents powered by OpenAI’s Codex harness and a DeepSeek model to target organizations at scale while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. This ransomware attack is believed to have originated from an IP address "45.142.193[.]132."
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-81578, CVE-2026-82078 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

45.142.•••.•••
pa•••••.html
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81578CVE-2026-81578 CVE-2026-82078CVE-2026-82078
Target & Sectors
TH HK RU CN IR
educationeducation
Incident Timeline
‎Sep 11, 2026
Threat actors exploited two actively known vulnerabilities in PaperCut, prompting the vendor to replace emergency patches with fixes for these flaws.
‎2026/09/11
Threat actors used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model to target organizations at scale, bypassing authentication and executing arbitrary code on susceptible instances.
organisation GreyNoise
organisation PaperCut Replaces Emergency Patches With Fixes
organisation Actively Exploited Flaws
victims 395 organizations
organisation OpenAI’s
infrastructure 26.0.5
infrastructure 25.0.13
infrastructure 24.1.10
organisation PaperCut NG/MF
organisation CVE-2026
organisation Vulnerability / Cyber Attack
organisation PaperCut
organisation QA
organisation IP
Tactical Metrics
Metrics
victims
395
Organizations
Metrics
infrastructure
‎26.0.5
Software Version
Metrics
infrastructure
‎25.0.13
Software Version
Metrics
infrastructure
‎24.1.10
Software Version