Full Report
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that
Analysis Summary
# Main Topic
**PaperCut NG/MF Security Maintenance Release for Two Actively Exploited CVEs**
The software vendor PaperCut issued a new regular maintenance release (MR) that supersedes earlier emergency patches for CVE‑2026‑81578 and CVE‑2026‑82078. These vulnerabilities, which allow bypass of authentication and arbitrary code execution, have been actively exploited in the wild. A suspected Russian‑speaking threat actor weaponised the flaws with AI‑powered automation to compromise at least 395 organizations, primarily in the U.S. education sector.
## Key Points
- **Active Exploitation** – CVE‑2026‑81578 & CVE‑2026‑82078 are being leveraged by attackers to gain unauthorised access and execute code on PaperCut instances.
- **Mass‑Scale Attack** – Attackers used hundreds of AI agents (OpenAI Codex & DeepSeek) to scan, exploit, and compromise organisations in 48 countries while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 others.
- **Target Profile** – The majority of compromised entities are in the U.S. education sector.
- **IP Indicator** – Exploitation activity originates from the source IP `45.142.193[.]132`.
- **Patch Availability** – PaperCut NG/MF versions 26.0.5, 25.0.13, and 24.1.10 include all emergency fixes plus additional hardening and are now available for download.
## Threat Actors
- **Suspected Russian‑speaking group** – Likely a state‑aligned or financially motivated actor, possibly using the exploits for credential harvesting or as a staging ground for further attacks (ransomware, data exfiltration).
- **Motivation** – Immediate gain via credential theft and potential for later exploitation; unclear if the actor intends to sell access or use it for follow‑on objectives.
## TTPs
- **Exploitation of Public‑Facing Application (T1190)** – Bypass authentication to gain code execution.
- **Automated Scanning & Exploitation** – Hundreds of AI agents orchestrated to scan for vulnerable PaperCut instances.
- **Credential Theft & Lateral Movement (T1078)** – After initial compromise, attackers harvest credentials for further internal exploitation.
- **Use of AI Models (Codex, DeepSeek)** – Automate discovery, exploitation, and post‑exploitation scripts.
- **Geographic Filtering** – Avoided specific countries, indicating targeted campaign behaviour.
## Affected Systems
- **Software** – PaperCut NG/MF
- **Versions** – 26.0.5, 25.0.13, 24.1.10 (pre‑MR versions that received emergency patches are now vulnerable)
- **Deployments** – Public‑facing or remotely accessible instances, especially within the U.S. education sector.
## Mitigations
- **Apply the Latest Maintenance Release** – Upgrade to PaperCut NG/MF 26.0.5, 25.0.13, or 24.1.10 immediately. The MR contains all emergency fixes plus additional hardening.
- **Disable or Restrict Remote Access** – Where possible, limit external exposure of PaperCut instances.
- **Network Segmentation & Access Controls** – Restrict inbound traffic to only required IP ranges; consider firewall rules to block known malicious IPs.
- **Monitoring & Detection** –
- Watch for failed authentication attempts or unusual login patterns.
- Detect exploitation traffic from `45.142.193[.]132` or other malicious IPs.
- Employ IDS/IPS signatures for CVE‑2026‑81578/CVE‑2026‑82078 exploitation attempts.
- **Patch Management** – Ensure all PaperCut instances are fully patched; schedule regular vulnerability scans to detect unpatched systems.
## Conclusion
PaperCut’s two CVEs are actively exploited with a large‑scale, AI‑driven campaign targeting educational institutions and other organizations worldwide. The threat actor’s use of automated agents and geographic filtering indicates a sophisticated, well‑resourced operation. Immediate patching to the latest maintenance release and tightening of network exposure are critical to mitigate risk. Continuous monitoring for exploitation attempts and IP-based blocking of known malicious actors will help contain potential breaches.