395 organizations in 48 countries were identified as victims of an automated campaign exploiting two actively used flaws—an infection pattern that pushed PaperCut to replace emergency fixes with full maintenance releases.
Vulnerabilities CVE-2026-81578 and CVE-2026-82078
Two vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, have been used in the wild to bypass authentication and execute arbitrary code on susceptible instances. That combination of capabilities—authentication bypass plus remote code execution—was the central rationale for the emergency patches PaperCut issued earlier and for the maintenance releases the company published on Thursday.
PaperCut releases 26.0.5, 25.0.13 and 24.1.10
PaperCut announced maintenance releases PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. In its statement the company called these "Regular Maintenance Releases (MR) that have gone through complete QA testing," and added, "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process."
PaperCut also said the maintenance releases supersede the emergency patches that addressed the two security flaws and two regressions, and that they include "various hardening and mitigation against potential attack chains." Customers running an emergency patch build were advised to move to a maintenance release for optimal protection.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageAI agents and a trace to IP 45.142.193[.]132
Security telemetry reported the campaign used "hundreds of AI agents" to scale targeting. Those agents were described as being powered by OpenAI’s Codex harness and a DeepSeek model. The activity was observed avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries, and was traced to infrastructure that originates from the IP address "45.142.193[.]132."
One case highlighted by GreyNoise and Blackpoint Cyber found a suspected Russian-speaking threat actor weaponizing the two flaws to break into at least 395 organizations in 48 countries, with the largest concentration in the U.S. education sector.
GreyNoise and Blackpoint Cyber's assessment
GreyNoise publicly assessed the campaign and flagged the uncertainty around the actor’s endgame. "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said. That statement frames the current risk as not only immediate compromise but also potential staging for further criminal operations.
What this means for security teams, the U.S. education sector, and adversaries
- Security teams and technologists: PaperCut’s maintenance releases consolidate earlier emergency fixes and introduce additional hardening; teams are advised to migrate from emergency patch builds to the listed MR versions to reduce exposure to authentication-bypass and remote-code-execution vectors.
- U.S. education sector and affected enterprises: With the campaign concentrated in the U.S. education sector and at least 395 organizations identified globally, institutions should prioritize applying the maintenance releases and review logs and access for signs of the AI-driven intrusion activity traced to "45.142.193[.]132."
- Adversaries and access brokers: The observed use of hundreds of AI agents and the selective avoidance of certain countries suggest an automated, high-volume access-development approach; whether that access will be monetized directly by the operator or sold to affiliates remains, in GreyNoise’s words, "unclear."
PaperCut’s move from emergency patches to fully tested maintenance releases is a concrete mitigation step, but the campaign’s scale—automated agents, a single traced IP, and hundreds of affected organizations—keeps the situation urgent. For defenders the immediate work is clear: apply the MR builds (26.0.5, 25.0.13, 24.1.10), hunt for indicators tied to the exploitation activity, and monitor for any follow-on data theft or ransomware activity stemming from the compromised access.
Read the original report: https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html




