PaperCut has released new maintenance updates that replace the emergency patches previously issued for two vulnerabilities being actively exploited in the wild. The new releases have completed the company’s standard QA process and include additional security hardening beyond the original fixes.
The updates are available as PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10. PaperCut says these releases incorporate all fixes from Emergency Patch Releases 1, 2 and 3, while also addressing regressions discovered during the earlier emergency response.
The primary vulnerabilities are CVE-2026-81578 and CVE-2026-82078. Attackers can combine the flaws to bypass authentication and execute arbitrary code on vulnerable PaperCut servers, creating a path toward full compromise of exposed installations.
The vulnerabilities have already been weaponized in significant attacks. Researchers from GreyNoise and Blackpoint Cyber linked exploitation to a suspected Russian-speaking threat actor that compromised at least 395 organizations across 48 countries, with the U.S. education sector particularly heavily targeted.
Researchers observed the attackers using hundreds of AI agents powered by OpenAI’s Codex harness and a DeepSeek model to automate operations at scale. The campaign originated from the IP address45.142.193[.]132and deliberately avoided organizations in Russia, China, Hong Kong, Thailand, Iran and several other countries.
It remains unclear what the attackers intend to do with the compromised systems. Researchers said the group could be building an inventory of accesses for other threat actors or preparing for follow-up activity such as data theft or ransomware deployment.
The concentration of attacks against educational organizations is especially concerning because PaperCut is widely used by schools and universities to manage printing infrastructure. A compromised PaperCut server could provide attackers with another foothold inside institutional networks and potentially expose credentials or facilitate lateral movement.
Organizations that previously installed one of PaperCut’s emergency patches should now migrate to the corresponding maintenance release. These versions supersede the temporary fixes and provide the more thoroughly tested and hardened versions intended for production environments.
With active exploitation already confirmed, administrators should prioritize the upgrade rather than treating it as routine maintenance. Systems exposed to the internet should also be investigated for signs of compromise, particularly if they remained vulnerable after exploitation began.