PaperCut releases tested maintenance fixes for exploited flaws

PaperCut replaces emergency patches with maintenance releases
PaperCut has issued regular maintenance releases for PaperCut NG/MF that replace emergency patches deployed for two vulnerabilities being actively exploited. Versions 26.0.5, 25.0.13 and 24.1.10 are available to customers.
The releases address CVE-2026-81578 and CVE-2026-82078, flaws that attackers have used to bypass authentication and execute arbitrary code on susceptible PaperCut instances. PaperCut said the new builds are regular maintenance releases that completed full quality-assurance testing.
They incorporate every security fix from Emergency Patch Releases 1, 2 and 3, alongside additional security hardening. The maintenance builds also went through PaperCut's standard release-testing process, rather than the accelerated process used for emergency patches.
What the new builds supersede
The new releases supersede the emergency patches issued for the two vulnerabilities, two regressions, and a range of hardening and mitigation measures intended to disrupt potential attack chains. Customers operating an emergency-patch build are advised to move to the applicable maintenance release.
The issue has practical urgency because exploitation is already occurring in the wild. Authentication bypass can give an unauthorised party access to a vulnerable service, while arbitrary code execution can allow attackers to run code on the affected instance.
Reported campaign targeted hundreds of organisations
GreyNoise and Blackpoint Cyber identified a suspected Russian-speaking threat actor weaponising the two flaws to breach at least 395 organisations across 48 countries. Most of the affected organisations were in the U.S. education sector.
The reported activity used hundreds of AI agents, powered by OpenAI's Codex harness and a DeepSeek model, to target organisations at scale. GreyNoise said the operation avoided entities in Russia, China, Hong Kong, Thailand, Iran and 23 other countries, and traced the activity to IP address 45.142.193[.]132.
GreyNoise said it was unclear whether the actor was focused only on developing access for affiliated actors or intended to use that access for later objectives, including data theft or ransomware deployment.
Business implication
Organisations using PaperCut NG/MF should identify systems still on emergency-patch builds, install the matching maintenance release, and review relevant exposure and logs in light of the reported exploitation activity.

