PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

Summary: PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

PaperCut has released new maintenance updates that replace the emergency patches previously issued for two vulnerabilities being actively exploited in the wild. The new releases have completed the company’s standard QA process and include additional security hardening beyond the original fixes.

The updates are available as PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10. PaperCut says these releases incorporate all fixes from Emergency Patch Releases 1, 2 and 3, while also addressing regressions discovered during the earlier emergency response.

The primary vulnerabilities are CVE-2026-81578 and CVE-2026-82078. Attackers can combine the flaws to bypass authentication and execute arbitrary code on vulnerable PaperCut servers, creating a path toward full compromise of exposed installations.

The vulnerabilities have already been weaponized in significant attacks. Researchers from GreyNoise and Blackpoint Cyber linked exploitation to a suspected Russian-speaking threat actor that compromised at least 395 organizations across 48 countries, with the U.S. education sector particularly heavily targeted.

Researchers observed the attackers using hundreds of AI agents powered by OpenAI’s Codex harness and a DeepSeek model to automate operations at scale. The campaign originated from the IP address45.142.193[.]132and deliberately avoided organizations in Russia, China, Hong Kong, Thailand, Iran and several other countries.

It remains unclear what the attackers intend to do with the compromised systems. Researchers said the group could be building an inventory of accesses for other threat actors or preparing for follow-up activity such as data theft or ransomware deployment.

The concentration of attacks against educational organizations is especially concerning because PaperCut is widely used by schools and universities to manage printing infrastructure. A compromised PaperCut server could provide attackers with another foothold inside institutional networks and potentially expose credentials or facilitate lateral movement.

Organizations that previously installed one of PaperCut’s emergency patches should now migrate to the corresponding maintenance release. These versions supersede the temporary fixes and provide the more thoroughly tested and hardened versions intended for production environments.

With active exploitation already confirmed, administrators should prioritize the upgrade rather than treating it as routine maintenance. Systems exposed to the internet should also be investigated for signs of compromise, particularly if they remained vulnerable after exploitation began.

Key facts

  • PaperCut released new security maintenance releases on Thursday
  • These releases replace all previously published emergency patches
  • The patches address two security flaws that have been actively exploited
  • Affected PaperCut NG/MF versions include 26.0.5, 25.0.13, and 24.1.10
  • The updates are described as Regular Maintenance Releases (MR)

Why it matters

The shift from emergency patches to regular maintenance releases suggests PaperCut has successfully developed and validated more comprehensive fixes for critical vulnerabilities. This is crucial for organizations relying on PaperCut's print management software, as it indicates a move towards a more stable and secure operational state, reducing the immediate risk associated with active exploitation and demonstrating a commitment to addressing security concerns through established update channels.