On Thursday, PaperCut announced the release of a comprehensive security update to replace previous emergency patches that were addressing two actively exploited vulnerabilities. These updates pertain to versions 26.0.5, 25.0.13, and 24.1.10 of PaperCut NG/MF, which are now accessible for customer download.
Significance of the Latest Updates
According to PaperCut, the new maintenance releases have undergone thorough quality assurance testing and include all the security enhancements from prior emergency patches. Additionally, they feature further security reinforcements and have been subjected to the company’s standard release testing procedures.
These updates not only supersede the emergency patches but also address two regressions and implement enhanced measures against potential attack vectors. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, have been actively exploited to bypass authentication and execute arbitrary code on vulnerable systems.
Exploitation by Cyber Threat Actors
Recent analyses by GreyNoise and Blackpoint Cyber reveal that a suspected Russian-speaking threat actor has been exploiting these vulnerabilities to breach approximately 395 organizations across 48 countries, with the majority located in the U.S. education sector.
The attacks employ a multitude of AI agents, utilizing OpenAI’s Codex and the DeepSeek model, to target organizations on a massive scale while deliberately avoiding entities in certain countries, including Russia and China. The malicious activities have been traced back to the IP address “45.142.193[.]132.”
Recommendations for PaperCut Users
GreyNoise has raised concerns about whether the threat actor’s primary aim is to develop access for other affiliated actors or to use the access for further objectives such as data theft or ransomware attacks.
Given the active exploitation of these vulnerabilities, PaperCut urges users to implement the latest security updates to ensure robust protection. Customers using an emergency patch build should transition to the new maintenance release promptly to safeguard their systems.
In conclusion, these updates are crucial for maintaining the security integrity of PaperCut systems amid ongoing exploitation attempts. Users are strongly encouraged to apply these fixes to mitigate risk and protect organizational data.
