PaperCut Addresses Two Actively Exploited Vulnerabilities with Permanent Fixes Instead of Emergency Patches

PaperCut Issues Security Update Amid Exploitation of Critical Vulnerabilities

On Thursday, PaperCut released a significant security maintenance update to address two critical vulnerabilities that have recently been exploited in the wild. This update replaces all previous emergency patches aimed at mitigating these issues, underscoring the urgency of the situation.

The software development firm has made available new versions of PaperCut NG/MF—specifically 26.0.5, 25.0.13, and 24.1.10—for users to download. According to the company, these Regular Maintenance Releases have undergone comprehensive quality assurance testing and include all security fixes previously included in Emergency Patch Releases 1, 2, and 3. Moreover, these updates come with enhanced security measures that have been validated through PaperCut’s standard release testing protocols.

This maintenance release supersedes earlier emergency patches that were designed to counteract the two vulnerabilities, along with addressing two regressions and providing various hardening techniques to mitigate potential attack vectors. The identified vulnerabilities, cataloged as CVE-2026-81578 and CVE-2026-82078, have been exploited to bypass authentication protocols and execute arbitrary code on susceptible systems.

The active exploitation of these vulnerabilities points to organized cybercriminal activity, particularly from a suspected Russian-speaking threat actor. Reports have indicated that this actor has exploited these flaws to breach the networks of at least 395 organizations across 48 countries, with a notable concentration in the U.S. education sector.

In executing these attacks, the actors reportedly utilized hundreds of AI-powered tools, leveraging OpenAI’s Codex and a DeepSeek model, to scale their operations while selectively avoiding entities located in Russia, China, and other specified countries. The malicious activity has been traced back to an IP address associated with a wider campaign.

GreyNoise, in collaboration with Blackpoint Cyber, has raised concerns about the potential objectives of this threat actor. It remains uncertain whether they are focused on developing access for subsequent exploitation by affiliated actors or if they intend to utilize their access for immediate goals such as data theft or the deployment of ransomware.

In light of these ongoing exploits, PaperCut strongly advises users to upgrade from any emergency patch builds to the latest maintenance release for optimal security. Business owners utilizing PaperCut’s services should recognize the importance of applying these updates to protect their systems from further breaches, given the sophistication of the threats currently at play.

The risk associated with these vulnerabilities is accentuated by the tactics identified in the MITRE ATT&CK framework, including initial access through exploitation of vulnerabilities, persistence mechanisms to retain unauthorized access, and privilege escalation strategies to enhance the actor’s control over compromised systems. As the cybersecurity landscape continues to evolve, staying informed and proactive is crucial for safeguarding business operations.

Source link