
PaperCut Ships Tested Fixes for Actively Exploited Flaws
PaperCut released maintenance versions 26.0.5, 25.0.13 and 24.1.10 to replace emergency patches for two flaws already under attack.
PaperCut has released new maintenance releases for PaperCut NG/MF that replace the emergency patches issued for two security flaws already being exploited in the wild. PaperCut NG and PaperCut MF are print management applications used by organizations to control printing, copying and scanning. The new versions are 26.0.5, 25.0.13 and 24.1.10, and PaperCut describes them as regular maintenance releases that have gone through complete QA testing, meaning quality assurance testing. According to the company, these releases contain all of the security fixes previously issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening. PaperCut also said the releases supersede the emergency patches that addressed two regressions, along with various hardening and mitigation against potential attack chains. The move replaces urgent, partially tested patches with fully tested updates, which matters for organizations that need reliable software.
The two vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, allow an attacker to bypass authentication and execute arbitrary code on a vulnerable PaperCut server. Authentication is the process a system uses to confirm who you are, and arbitrary code execution means an intruder can run their own commands on the machine. When a flaw like this is actively exploited, attackers are already using it against real systems, not just in theory. PaperCut has not released technical details beyond the CVE identifiers, but the warning is clear: these holes are being used right now to break into exposed instances.
Security researchers from GreyNoise and Blackpoint Cyber have documented a suspected Russian-speaking threat actor using the two flaws to compromise at least 395 organizations across 48 countries, with the largest concentration in the United States education sector. A threat actor is a person or group behind a cyberattack. The researchers observed that the attacks used hundreds of AI agents, powered by OpenAI's Codex harness and a DeepSeek model, to target organizations at scale while deliberately avoiding entities in Russia, China, Hong Kong, Thailand, Iran and 23 other countries. The activity, they said, originates from the IP address 45.142.193[.]132. An IP address is a numerical label that identifies a device on a network. GreyNoise noted that it is unclear whether the actor is only building access to hand off to other groups, or will directly use that access for data theft or ransomware deployment.
For any organization running PaperCut NG or MF, the practical advice is straightforward. PaperCut says customers who installed an emergency patch build should move to a maintenance release as soon as possible. The new versions are available for download now. Because the flaws are already under active exploitation, waiting to patch gives attackers more time to break in. Even if an organization does not use PaperCut, the episode is a reminder that any internet-facing server software, including print management, web hosting panels and content management systems, needs the same prompt attention when a vendor ships a security update. An unpatched server can become the entry point for a much larger compromise.
For website owners, businesses and IT teams, the response starts with an inventory of what you run and who is responsible for patching it. If you use PaperCut, install version 26.0.5, 25.0.13 or 24.1.10 now, or ask your administrator to do it. Check that any emergency patch has been replaced by a maintenance release, because only the maintenance releases have gone through full QA testing. Watch for unexpected logins or new administrator accounts on print servers and web servers. For teams that manage multiple servers or lack the time to test patches, working with a security-focused IT partner such as AEU-I can help keep PaperCut and other infrastructure patched before attackers exploit known flaws.
How to Protect Yourself
- If your organization uses PaperCut, ask your IT administrator to install the latest maintenance release (26.0.5, 25.0.13 or 24.1.10) right away.
- Turn on automatic updates for any server software you manage so security fixes are applied without delay.
- Use a unique, strong password and two-factor authentication for your PaperCut admin account and any other admin panels.
- Check your server logs for unusual activity, such as logins from unexpected countries or at odd hours.
- If you are not sure whether your systems are patched, contact your hosting provider or IT support to confirm.
Vulnerabilities & Fixes
- CVE-2026-81578 A vulnerability in PaperCut NG/MF that can be exploited to bypass authentication and execute arbitrary code; fixed in maintenance releases 26.0.5, 25.0.13 and 24.1.10. View the fix & details →
- CVE-2026-82078 A vulnerability in PaperCut NG/MF that can be exploited to bypass authentication and execute arbitrary code; fixed in maintenance releases 26.0.5, 25.0.13 and 24.1.10. View the fix & details →
Terms Explained
- CVE Common Vulnerabilities and Exposures, a public list that gives each known security flaw a unique number.
- authentication The process a system uses to confirm who you are before letting you in.
- arbitrary code execution A type of attack where an intruder can run their own commands on a vulnerable system.
- threat actor A person or group responsible for a cyberattack.
- IP address A numerical label that identifies a device on a network.
- QA testing Quality assurance testing, checking that software works correctly before it is released.
- maintenance release A software update that has been fully tested and includes fixes and improvements.