Back to feed

PaperCut releases maintenance updates fixing two actively exploited flaws

1 min
PaperCut releases maintenance updates fixing two actively exploited flaws

This digest was compiled by AI from multiple sources — links to the originals are below.

PaperCut released maintenance releases 26.0.5, 25.0.13 and 24.1.10 on Thursday, replacing emergency patches for two actively exploited vulnerabilities. The flaws, CVE-2026-81578 and CVE-2026-82078, allow authentication bypass and remote code execution. A suspected Russian-speaking threat actor has used them to breach at least 395 organizations in 48 countries.

Key Facts

  • PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 replace all previously published emergency patches.
  • The vulnerabilities CVE-2026-81578 and CVE-2026-82078 are being actively exploited to bypass authentication and execute arbitrary code.
  • A suspected Russian-speaking threat actor has breached at least 395 organizations in 48 countries, mostly in the U.S. education sector.
  • The attacks used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model, originating from IP address 45.142.193.132.
  • PaperCut advises customers running emergency patch builds to move to the new maintenance releases.

Maintenance Releases

PaperCut released maintenance releases 26.0.5, 25.0.13 and 24.1.10 on Thursday. These releases replace all emergency patches previously issued for two actively exploited security flaws. The company said the releases are regular maintenance releases that have gone through complete QA testing. They contain all security fixes from Emergency Patch Releases 1, 2 and 3, plus additional security hardening.

Exploitation Campaign

GreyNoise and Blackpoint Cyber identified a suspected Russian-speaking threat actor weaponizing the two flaws. The actor breached at least 395 organizations in 48 countries, with most victims in the U.S. education sector. The attacks used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model. The activity originates from IP address 45.142.193.132 and avoids entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries.

1 source

Time · lag behind first