PaperCut has rolled out updated versions of its NG/MF software—26.0.5, 25.0.13, and 24.1.10—that consolidate emergency security patches addressing two vulnerabilities currently being exploited. These updates replace all previous emergency patches and introduce extra protections, having undergone full QA and standard release testing processes. The new maintenance releases also fix two regressions and include hardening to mitigate potential attack chains.
What’s at Risk
The addressed vulnerabilities—CVE-2026-81578 and CVE-2026-82078—enable attackers to bypass authentication checks and execute arbitrary code on vulnerable systems. Stealthy actors have exploited these flaws in real-world attacks, compromising at least 395 organizations across 48 countries. The most heavily impacted sector: U.S. education.
The attacks involve hundreds of AI agents using OpenAI’s Codex and a model named DeepSeek to automate and scale intrusion operations. These agents avoid targeting entities in Russia, China, Hong Kong, Thailand, Iran, and others, operating from IP address 45.142.193[.]132, based on threat intelligence collected by GreyNoise and Blackpoint Cyber.
Recommended Response
Organizations still running the emergency patch builds are urged to upgrade immediately to the latest maintenance releases to benefit from all accumulated fixes and improved safeguards. The new versions are intended to supersede Emergency Patch Releases 1 through 3, encompassing their fixes.
These maintenance releases not only include the fixes for the two CVEs but also address regressions introduced in earlier patches. PaperCut emphasizes that these are full maintenance builds, meaning these fixes have passed routine testing and include security hardening to reduce exposure from related attack chains.
With active exploitation already underway, delayed patching could allow attackers continued access, potential data theft, or even ransomware deployment in affected environments.
Understanding PaperCut: this software is often used in enterprise printing environments—NG/MF stands for Network Gateway/Multi-Function—managing large printer fleets and document workflows. When vulnerabilities allow an attacker to bypass authentication or execute commands remotely, the security risks multiply quickly, especially in institutional settings like schools or universities.
What this means: for IT teams in education and any organization reliant on PaperCut, the stakes are high. Applying these maintenance releases promptly closes off known exploit paths and ensures that no lingering weaknesses from emergency patches remain. Monitoring for connections from suspicious agents and anomalous authentication failures is also advised.