Exploits

PaperCut Releases New Maintenance Update for Exploited Flaws

Published  ·  4 min read

If you're running PaperCut NG or MF, you need to update again. The company just released new maintenance releases that replace all the emergency patches they pushed out earlier. And this time, the updates have gone through full quality assurance testing.

PaperCut announced the new releases on Thursday. Versions 26.0.5, 25.0.13, and 24.1.10 are now available. The Hacker News covered the announcement.

Here's what you need to know.

Quick Summary

What

Details

New Releases

26.0.5, 25.0.13, 24.1.10

Replaces

Emergency Patch Releases 1, 2, and 3

Vulnerabilities

CVE-2026-81578, CVE-2026-82078

Status

Active exploitation

Campaign Scale

395 organizations, 48 countries

Attacker IP

45.142.193[.]132

What's in the New Release?

PaperCut says these are "Regular Maintenance Releases" that have gone through complete QA testing. They contain all the security fixes from the emergency patches, plus additional security hardening.

What They Replace:

  • Emergency Patch Release 1
  • Emergency Patch Release 2
  • Emergency Patch Release 3
  • Two regressions from those patches
  • Various hardening and mitigations against potential attack chains

The emergency patches were released quickly to address the immediate threat. But they weren't fully tested. The new maintenance releases are.

Why This Matters:

If you applied an emergency patch, you should move to a maintenance release. PaperCut says customers running an emergency patch build should upgrade.

The Vulnerabilities

The two flaws are CVE-2026-81578 and CVE-2026-82078. Together, they allow an attacker to bypass authentication and execute arbitrary code on vulnerable PaperCut instances.

The Impact:

An attacker who exploits these flaws can:

  • Bypass authentication
  • Execute code remotely
  • Gain full control of the PaperCut server
  • Move laterally into the network

These aren't theoretical vulnerabilities. They're being actively exploited in the wild.

The Active Exploitation Campaign

The Hacker News reported on a campaign that's been using these flaws to break into organizations at scale. GreyNoise and Blackpoint Cyber tracked the activity.

The Numbers:

Metric

Number

Compromised instances

440

Victim organizations

395

Countries affected

48

Primary target

U.S. education sector

The Attacker:

A suspected Russian-speaking threat actor. The action comes from the IP address 45.142.193[.]132.

Connection between AI and the Attack:

What makes the mentioned attack unique is that the hundreds of AI agents, which were controlled via the OpenAI Codex harness and DeepSeek model, participated in the process.

The attacker also tried to avoid targeting entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. But GreyNoise noted that the "attempted restraint failed in some instances."

What We Don't Know:

"It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said.

What You Should Do

1. Update to the Latest Maintenance Release

  • PaperCut NG/MF 26.0.5
  • PaperCut NG/MF 25.0.13
  • PaperCut NG/MF 24.1.10

If you're running an emergency patch build, move to one of these maintenance releases.

2. Indicators of Compromise

Look for the following:

  • Unusual outbound connections
  • Unusual registry changes
  • Unusual process creation
  • Unusual admin accounts

3. Assess Your Vulnerability

Is your PaperCut server Internet-exposed? Do you need to be? Make sure that only authorized networks can access the server.

4. Identify Indicators of AI-enabled Behavior

Signs that indicate attempts to exploit vulnerabilities using automation include:

  • Retry attacks
  • System enumeration
  • Multi-system attacks

The Bottom Line

PaperCut has released new maintenance updates that replace the emergency patches for CVE-2026-81578 and CVE-2026-82078. These releases have gone through full QA testing and include additional hardening. Active exploitation continues, so if you haven't updated yet, do it now.

What You Need to Know:

Key Point

Detail

New Releases

26.0.5, 25.0.13, 24.1.10

Replaces

Emergency Patch Releases 1, 2, 3

Vulnerabilities

CVE-2026-81578, CVE-2026-82078

Status

Active exploitation

Campaign Scale

395 organizations, 48 countries


What You Need to Do:

  • Update to the latest maintenance release
  • Check for indicators of compromise
  • Review your exposure
  • Monitor for AI-assisted activity

FAQ Section

What is the new PaperCut release?

PaperCut released maintenance versions 26.0.5, 25.0.13, and 24.1.10. These replace the emergency patches for CVE-2026-81578 and CVE-2026-82078 and include additional security hardening.

Why did PaperCut release updates?

Emergency patching was done to fix a problem that is being exploited. New maintenance patches have been tested and resolve the regression in emergency patches.

Which vulnerabilities does the update patch?

CVE-2026-81578 and CVE-2026-82078 allow authentication bypass and remote code execution.

Are these vulnerabilities being exploited?

Yes. A suspected Russian-speaking actor has compromised at least 395 organizations in 48 countries.

What should I do if I applied an emergency patch?

Upgrade to one of the new maintenance releases. PaperCut says customers running emergency patch builds should move to a maintenance release.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067