PaperCut Ships Maintenance Release for Two Actively Exploited Auth Bypass Flaws
PaperCut has rolled out Regular Maintenance Releases (MR) — versions 26.0.5, 25.0.13, and 24.1.10 — that supersede the three emergency patches previously shipped for PaperCut NG/MF. The new builds incorporate all prior security fixes plus additional hardening and mitigations against potential attack chains, and have completed full QA testing through the vendor's standard release process. Organizations currently running an emergency patch build are urged to migrate to the maintenance release immediately.
The underlying flaws, tracked as CVE-2026-81578 and CVE-2026-82078, are authentication bypass and arbitrary code execution vulnerabilities that have been actively weaponized in the wild. According to GreyNoise and Blackpoint Cyber, a suspected Russian-speaking threat actor operating from IP address 45.142.193[.]132 has exploited the pair to compromise at least 395 organizations across 48 countries — with the U.S. education sector bearing the brunt of the activity. The campaign notably used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model to scale targeting, while deliberately steering clear of entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. Defenders can run a WHOIS lookup on that address or use a port scanner to identify exposed PaperCut management consoles on their perimeter.
"It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise noted. The use of autonomous AI agents to enumerate and exploit victims at scale marks a notable escalation in tradecraft, lowering the operator cost per target and accelerating dwell time across affected networks. Security teams should treat any internet-exposed PaperCut instance as compromised until proven otherwise, audit logs for indicators linked to 45.142.193[.]132, and rotate administrative credentials — a worthwhile moment to verify exposed credentials with a password checker and an email breach checker.
With confirmed in-the-wild exploitation already underway and a clear preference for education-sector targets, applying the latest fixes is non-negotiable. PaperCut customers should patch without delay, restrict management interfaces to trusted networks, and monitor for the post-exploitation behaviors commonly associated with these CVE chains.