PaperCut flaws let an AI-run crew seize domain admin at 395 firms

GreyNoise says an intruder used AI agents to exploit two PaperCut print-management bugs and reach domain administrator rights at hundreds of organizations.

MedRisk Staff
By
2 Min Read

Two bugs in PaperCut print-management software handed an intruder a way into hundreds of networks, with AI agents doing most of the legwork, GreyNoise reports.

Investigators counted at least 440 compromised PaperCut instances tied to 395 identified organizations across 48 countries. To weaponize CVE-2026-81578 and CVE-2026-82078, the operator stood up a private lab holding a vulnerable PaperCut NG/MF build next to an Active Directory server.

Speed was the striking part. Within roughly four hours the intruder moved from a blank workspace to remote code execution on a live target, and two hours after that held domain administrator rights. The agents ran on OpenAI’s Codex harness paired with a DeepSeek model, plus public offensive tooling.

PaperCut acknowledged the exploitation in late August and pushed emergency patches, warning customers to keep the Application Server off the public internet.

The healthcare angle is direct. PaperCut is widely used in hospitals and clinics for secure print release and badge-based printing, and it often sits on the same directory an organization uses for clinical and email accounts. A domain-admin foothold gained through print infrastructure can open a path toward electronic health record systems.

Healthcare IT teams should confirm the patches are applied, pull the PaperCut server off the public internet, audit for rogue administrative accounts, and treat any domain-admin anomaly as a potential breach.

Share This Article