PAPERCUT has issued a maintenance release for PaperCut NG/MF that supersedes all previous emergency patches. The new MR (maintenance release) packages, versions 26.0.5, 25.0.13 and 24.1.10, contain all fixes from Emergency Patch Releases 1, 2 and 3 as well as additional hardening. PaperCut states these updates have passed their standard QA and testing processes and are intended to address two actively exploited flaws and two related regressions, along with mitigations to reduce attack chains.
The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have been exploited in the wild to bypass authentication and allow arbitrary code execution on affected systems. In a case highlighted by GreyNoise and Blackpoint Cyber, a suspected Russian-speaking actor leveraged these flaws to compromise at least 395 organisations across 48 countries, with a concentration in the U.S. education sector.
The operation reportedly used hundreds of AI agents powered by OpenAI Codex and a DeepSeek model to scale access, while attempting to avoid targets in Russia, China, Hong Kong, Thailand, Iran and 23 other nations. GreyNoise cautioned that it remains unclear whether the actor seeks direct follow-on objectives or will hand off access for data theft or ransomware.
Users with emergency patch builds are advised to upgrade to a maintenance release promptly to ensure protection. The article notes the importance of applying the latest fixes for optimal defence.