[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHJlGJ6vXo0vO-NEBzz97RcipRMFgAynB8StNzsdbHOw":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"6989e0a7-dcdc-4f74-b0f1-cce19fba6dbf","PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws","papercut-replaces-emergency-patches-with-fixes-for-two-actively-exploited-flaws-af3b87","PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG\u002FMF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. \"These are Regular Maintenance Releases (MR) that","PaperCut has issued new maintenance releases (versions 26.0.5, 25.0.13, and 24.1.10) that replace previous emergency patches for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078. These flaws allow for authentication bypass and arbitrary code execution. A suspected Russian-speaking threat actor has been exploiting these vulnerabilities to target over 395 organizations globally, with a focus on the U.S. education sector, using hundreds of AI agents powered by OpenAI's Codex and a DeepSeek model.","PaperCut releases fixes for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078.","PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Ravie LakshmananSep 11, 2026Vulnerability \u002F Cyber Attack PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG\u002FMF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. \"These are Regular Maintenance Releases (MR) that have gone through complete QA testing,\" it said. \"They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process.\" It's worth noting that the release supersedes the emergency patches that were shipped to address two security flaws as well as two regressions, along with various hardening and mitigation against potential attack chains. The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances. In one case highlighted by GreyNoise and Blackpoint Cyber, a suspected Russian-speaking threat actor has been found weaponizing the two flaws to break into at least 395 organizations in 48 countries, most of them concentrated in the U.S. education sector. The attacks used hundreds of AI agents, powered by OpenAI’s Codex harness and a DeepSeek model, to target organizations at scale, while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originates from the IP address \"45.142.193[.]132.\" \"It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment,\" GreyNoise said. In light of active exploitation efforts, it's imperative that users apply the latest fixes for optimal protection. PaperCut customers running an emergency patch build are advised to move to a maintenance release. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cyber Attack, Vulnerability ⚡ Top Stories This Week Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fpapercut-replaces-emergency-patches.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhT6b7k7Y60TgLLmuruqSocYNfZoYEmONgga8CidWSXIdOZLWlgCYLuXOe9bWQRi_3BRkOmJvPNANZAOS85Xx6RtuQTVCg2-QNi3dXfELQm8bglTMUK9rn54e-sLoslCkVYlPGiyGSnsu58yxo9EkC3PvXDWVTYhTRgDQqTDAQTs69vPBh7xjq0Fwm7bY40\u002Fs1600\u002Fpapercut-flaws.jpg","2026-09-11T06:46:18+00:00","2026-09-11T08:00:04.429808+00:00",9,[18,21,24,27,30,32],{"name":19,"type":20},"PaperCut NG\u002FMF","product",{"name":22,"type":23},"PaperCut","vendor",{"name":25,"type":26},"Russian-speaking threat actor","threat_actor",{"name":28,"type":29},"AI agents","technology",{"name":31,"type":20},"Codex",{"name":33,"type":20},"DeepSeek","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":34,"icon":36,"name":37,"slug":38},null,"Vulnerabilities","vulnerabilities",[40,45,47,52],{"category":41},{"id":42,"icon":36,"name":43,"slug":44},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":46},{"id":34,"icon":36,"name":37,"slug":38},{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":53},{"id":54,"icon":36,"name":55,"slug":56},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[58,62,64],{"type":59,"value":60,"context":61},"cve","CVE-2026-81578","Actively exploited vulnerability in PaperCut NG\u002FMF.",{"type":59,"value":63,"context":61},"CVE-2026-82078",{"type":65,"value":66,"context":67},"ip","45.142.193.132","Originating IP address for attacks exploiting PaperCut vulnerabilities."]