PaperCut Replaces Emergency Patches With Comprehensive Security Fixes

PaperCut has issued new maintenance releases that supersede previous emergency patches, addressing two flaws currently under active exploitation by state-linked actors.
PaperCut has released new maintenance versions of its NG/MF software to replace the emergency patches distributed earlier this week. The company states that these new builds have undergone full quality assurance testing and include all prior security fixes, along with additional hardening measures. This move aims to provide a more stable and thoroughly tested solution for organizations facing active threats.
The update addresses two specific vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, which allow attackers to bypass authentication and execute arbitrary code on affected systems. While the initial patches were deployed rapidly to stop ongoing attacks, the new releases are intended to be the standard long-term fix, replacing the stopgap measures previously advised to customers.
Active Exploitation Targets Education Sector
According to reports from GreyNoise and Blackpoint Cyber, a suspected Russian-speaking threat actor is actively weaponizing these flaws. The actor has compromised at least 395 organizations across 48 countries, with a significant concentration of targets in the United States education sector. The attacks are characterized by their scale and automated nature, suggesting a sophisticated operation rather than isolated incidents.
The threat actor is reportedly using hundreds of AI agents, powered by OpenAI’s Codex harness and a DeepSeek model, to conduct these intrusions efficiently. Notably, the campaign appears to deliberately avoid organizations located in Russia, China, Hong Kong, Thailand, Iran, and several other nations. This geographic exclusion pattern is a common indicator of state-sponsored or state-aligned cyber operations.
Uncertain Goals of the Intruder
Security researchers note that the ultimate objective of the actor remains unclear. It is uncertain whether the primary goal is to develop access for handoff to other affiliated groups or to directly leverage the compromised systems for follow-on objectives such as data theft or ransomware deployment. The use of AI-driven automation suggests an intent to maximize efficiency and coverage, potentially making detection more difficult for defenders.
Immediate Action Required for Users
Given the active exploitation of these vulnerabilities, applying the latest fixes is critical for maintaining system integrity. PaperCut advises customers currently running any of the emergency patch builds to transition immediately to the new maintenance releases. These versions are available for download and are designed to provide optimal protection against the specific attack chains observed in the wild.






