โ Back to FeedPaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
September 11, 2026 ยท The Hacker News ยท Severity: HIGH
PaperCut released new security maintenance updates replacing emergency patches for two actively exploited vulnerabilities in its print management software. The original emergency patches were interim measures, and the new permanent fixes address the underlying flaws more comprehensively. Given active exploitation, organizations must apply these updates urgently regardless of previous emergency patch status.
๐ **Analyst Note:** The replacement of emergency patches with more comprehensive fixes is a pattern that often signals the original vulnerabilities were more complex or had broader impact than initially understood. Organizations should treat this as a full re-patching event, not a minor update.
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said. "They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process." It's worth noting that the release supersedes the emergency patches that were shipped to address two security flaws as well as two regressions, along with various hardening and mitigation against potential attack chains. The vulnerabilities, CVE-2026-81578 and CVE-2026-82078 , have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances. In one case highlighted by GreyNoise and Blackpoint Cyber , a suspected Russian-speaking threat actor has been found weaponizing the two flaws to break into at least 395 organizations in 48 countries, most of them concentrated in the U.S. education sector . The attacks used hundreds of AI agents, powered by OpenAIs Codex harness and a DeepSeek model, to target organizations at scale, while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originates from the IP address "45.142.193[.]132." "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said. In light of active exploitation efforts, it's imperative that users apply the latest fixes for optimal protection. PaperCut customers running an emergency patch build are advised to move to a maintenance release. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- PaperCut has replaced emergency security patches with permanent fixes for two actively exploited vulnerabilities, indicating that the original emergency mitigations were incomplete or causing operational issues.
- The vulnerabilities are being actively exploited in the wild, making this a critical patching priority for all organizations running PaperCut print management software across any deployment model.
- The transition from emergency patches to permanent fixes suggests the vulnerabilities are more complex than initially assessed, and organizations should verify patching status regardless of whether emergency patches were previously applied.