PaperCut Releases New Security Fixes Amidst Active Exploitation by AI-Powered Threat Actor
Software provider **PaperCut** has issued new security maintenance releases to supersede previous emergency patches, addressing two actively exploited vulnerabilities, **CVE-2026-81578** and **CVE-2026-82078**. These flaws allow for authentication bypass and arbitrary code execution, with a sophisticated, AI-powered threat actor already leveraging them against hundreds of organizations globally, particularly in the U.S. education sector.

**PaperCut**, a leading software development company, announced new security maintenance releases on Thursday. These updates replace all previously issued emergency patches designed to counter two critical security flaws currently under active exploitation.
### Comprehensive Security Upgrades
**PaperCut NG/MF** versions 26.0.5, 25.0.13, and 24.1.10 are now available for download. These are standard maintenance releases that have undergone full Quality Assurance (QA) testing.
According to **PaperCut**, these new versions incorporate all security fixes from Emergency Patch Releases 1, 2, and 3, alongside additional security hardening and mitigations against potential attack chains. This comprehensive update also addresses two regressions identified in prior patches.
### Actively Exploited Vulnerabilities
The vulnerabilities in question, **CVE-2026-81578** and **CVE-2026-82078**, are being actively exploited in the wild. Attackers are chaining these flaws to bypass authentication and execute arbitrary code on vulnerable **PaperCut** instances.
### AI-Powered Attacks Target Education Sector
Security researchers at **GreyNoise** and **Blackpoint Cyber** have observed a suspected Russian-speaking threat actor weaponizing these two flaws. This actor has successfully breached at least 395 organizations across 48 countries, with a significant concentration in the U.S. education sector.
The attacks are notable for their sophisticated use of hundreds of AI agents, powered by **OpenAIβs Codex harness** and a **DeepSeek model**. This approach allows the threat actor to target organizations at scale while deliberately avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The malicious activity has been traced to the IP address "45.142.193[.]132."
**GreyNoise** noted that the actor's ultimate objectives remain unclear, stating: "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment."
### Urgent Call to Action
Given the active exploitation of these vulnerabilities, it is critically important for all **PaperCut** users to apply the latest maintenance releases immediately for optimal protection. Customers currently running an emergency patch build are strongly advised to transition to a maintenance release.