PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
PaperCut has released a new security update to address two actively exploited vulnerabilities, replacing previous emergency patches. The update resolves the flaws and includes additional security hardening, following reports of a Russian-speaking threat actor leveraging these vulnerabilities to target organizations globally, particularly in the U.S. education sector, using AI agents.
PaperCut released a new security maintenance release on Thursday, effectively replacing all previously published emergency patches. This update addresses two security flaws that have been under active exploitation. The software development company stated that PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for download.
These maintenance releases incorporate all security fixes from Emergency Patch Releases 1, 2 and 3, alongside additional security hardening measures.
Two vulnerabilities are being addressed: CVE-2026-81578 and CVE-2026-82078.
GreyNoise and Blackpoint Cyber reported that a suspected Russian-speaking threat actor has been utilizing these flaws to gain unauthorized access to at least 395 organizations across 48 countries, with a significant concentration in the U.S. education sector. The attacker employed hundreds of AI agents, utilizing OpenAI’s Codex and a DeepSeek model, to systematically target organizations while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originated from the IP address "45.142.193[.]132."
It remains unclear whether the actor’s goal is solely to establish access for handover to other affiliated actors or to directly exploit gained access for objectives such as data theft or ransomware deployment.
Given the ongoing exploitation efforts, users are strongly advised to immediately apply the latest maintenance release to ensure optimal protection.
