Skip to content
cve — cve-2026-81578

grep -rl "CVE-2026-81578" ./articles

CVE-2026-81578

GreyNoise watched a likely Russian-speaking operator point hundreds of AI agents at PaperCut and compromise 440 instances across 395 organisations. The operator's exclusion list held only partly: 18 victims sit in countries the agents were told to skip, every one of them from the back half of the list.

2 articles — 2026-09-07 to 2026-09-11

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The print server held the LDAP bind credentials. That is what they came for

2026-09-07Security

Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.

../cve — every identifier we have covered