FR
live
Security Critical

PaperCut replaces emergency patches with a hardened release after 395 organizations were compromised

On September 10, 2026, PaperCut published NG/MF versions 26.0.5, 25.0.13, and 24.1.10, replacing three emergency patches and closing two actively exploited flaws, CVE-2026-81578 and CVE-2026-82078. If you are still running an emergency patch, move to the maintenance release now.

A single white sheet of paper half-fed and jammed in the feed rollers of a laser printer.

September 10, 2026. PaperCut published a maintenance release that replaces three emergency patches and closes two flaws already exploited in the wild. Versions 26.0.5, 25.0.13, and 24.1.10 of PaperCut NG/MF have passed the full QA process. Why it matters: GreyNoise and Blackpoint Cyber document a suspected Russian-speaking actor that has already breached 395 organizations across 48 countries, concentrated on the US education sector.

Two CVEs chained to bypass authentication and run code

The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, are chained in the wild to bypass authentication and then execute arbitrary code on vulnerable instances. PaperCut had initially handled them with three successive emergency patches — Emergency Patch Releases 1, 2, and 3 — which also fixed two regressions and added hardening against potential attack chains.

This week’s maintenance release is different in kind. Where emergency patches ship without full validation, versions 26.0.5, 25.0.13, and 24.1.10 went through the standard test cycle. They bundle all the security fixes from the three emergency patches, plus additional hardening.

For a product deployed across schools, universities, and small businesses, the distinction matters: an emergency patch stops the bleeding, a maintenance release restores confidence in the update chain.

A Russian-speaking actor, 395 organizations, hundreds of AI agents

GreyNoise and Blackpoint Cyber describe a suspected Russian-speaking actor that weaponized the two flaws to break into 395 organizations across 48 countries, mostly in the US education sector.

The execution method is the most alarming signal. The attacks used hundreds of AI agents, powered by OpenAI’s Codex harness and a DeepSeek model, to target organizations at scale while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originates from the IP address 45.142.193[.]132.

The open question, raised by GreyNoise, is whether this actor is focused solely on developing access to hand off to other groups, or whether it will directly leverage that access for data theft or ransomware deployment. In either scenario, the already-compromised organization remains the victim.

What the print infrastructure team should do

A PaperCut instance is not a niche exposure. PaperCut NG/MF manages print queues, quotas, and billing for tens of millions of users, often in institutions whose network is historically flat and lightly segmented. Code execution on the print server opens the door to the rest of the network.

  • Identify your version — check whether you run 26.x, 25.x, or 24.x and compare against the patched releases;
  • Move to the maintenance release — emergency patches are no longer the reference, releases 26.0.5, 25.0.13, and 24.1.10 supersede them and add hardening;
  • Do not stay on an emergency patch — it closes the hole but lacks the additional QA-validated protections;
  • Hunt the IP and IOCs — the indicator 45.142.193[.]132 and the attack chains documented by GreyNoise and Blackpoint must enter your detection rules;
  • Segment the print server — a PaperCut instance does not need to reach the whole network, narrow its surface before the next flaw.

Verdict

PaperCut does not disclose the total number of exposed instances, but confirmed active exploitation combined with a heavily targeted education sector is enough to rank this update as urgent. The tipping point is not technical but organizational: teams that were applying emergency patches on the fly must now make the cutover to the stabilized release.

If you operate a PaperCut NG/MF instance, move to 26.0.5, 25.0.13, or 24.1.10 today, then check your logs for the IP 45.142.193[.]132 before considering the machine clean.

If you are in education or a small business without a dedicated security team, the real risk is not this flaw but the next one: segment the print server and automate its updates, because such a central product should no longer depend on manual intervention.

References

cve

Linked vulnerabilities

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Check Point patches two CVSS 9.8 flaws in its VPN certificate handling

On September 9, 2026, Check Point fixed two CVSS 9.8 flaws in how its firewalls and management console validate and decode VPN certificates, both exploitable without authentication for remote code execution. The Dutch NCSC says exploitation is imminent: apply the Live Patch or the Jumbo Hotfix now.

Ransomware gangs now exploit the unauthenticated IKEv2 RCE in WatchGuard Firebox firewalls

CISA updated its KEV entry on September 10, 2026 to confirm that CVE-2025-14733, an unauthenticated RCE in the WatchGuard Firebox iked process patched back in December 2025, is now used in ransomware attacks. With nearly 9,000 Fireboxes still exposed online, check your Fireware OS version and hunt for the indicators of compromise before the encryption starts.

← Back to the feed

Type at least two characters.

navigate open esc dismiss