Skip to content

Security1 publisher2 min readPublished

PaperCut folds three rounds of emergency patches into QA-tested maintenance builds

PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 carry every fix from three emergency patch rounds plus two regression fixes, while GreyNoise and Blackpoint Cyber count at least 395 organizations already breached.

The Watch · Security desk

Illustration accompanying PaperCut folds three rounds of emergency patches into QA-tested maintenance builds

What happened

  • PaperCut shipped NG/MF 26.0.5, 25.0.13 and 24.1.10. The three builds replace every emergency patch published for two flaws already exploited in the wild.
  • The campaign ran hundreds of AI agents on OpenAI's Codex harness with a DeepSeek model and skipped targets in Russia, China, Hong Kong, Thailand, Iran and 23 further countries.
  • The maintenance releases also carry fixes for two regressions from the emergency patch series, plus hardening and mitigation against potential attack chains.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Sites that patched fastest face a second change window, because the regression fixes exist only in the maintenance builds.
  • exposure Any PaperCut instance reachable before the first emergency patch may already have run attacker code. The upgrade leaves that question open.
  • capability Hundreds of coordinated agents let one operator work 48 countries at once, so the gap between a fix and mass exploitation is paced by the attacker's automation.
  • constraint Whether the campaign is still running is a separate question from whether the vendor is back to normal release testing.

Two regressions came out of the emergency patch series. The new builds carry the fixes for them [5]. That is the case for rebuilding even where the first hotfix went in cleanly. PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are the first builds to take the whole fix set through the vendor's normal test process [2]. Each supported branch now has one tested build in place of three rounds of hotfixes [13]. "These are Regular Maintenance Releases (MR) that have gone through complete QA testing," PaperCut said [3]. The company said they contain "all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process" [4].

CVE-2026-81578 and CVE-2026-82078 have been used in the wild to bypass authentication and execute arbitrary code [6]. GreyNoise and Blackpoint Cyber tie that pair to a suspected Russian-speaking actor with at least 395 victim organizations across 48 countries, most of them in the U.S. education sector [7]. The operation ran hundreds of AI agents built on OpenAI's Codex harness and a DeepSeek model, working from the address 45.142.193.132 [8][9]. The targeting filter excluded 28 countries, among them Russia, China, Hong Kong, Thailand and Iran [12].

What the actor intends to do with those footholds is unsettled. "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said [10]. Upgrading closes the exploit path and leaves untouched whatever code an intruder already executed on a server that was reachable before the fix went on [6].

PaperCut's release statement and GreyNoise's assessment both stop short of saying the exploitation has stopped [14]. The maintenance releases change what a fleet can be standardised on, and a version inventory against 26.0.5, 25.0.13 and 24.1.10 is now answerable in one pass [2]. PaperCut's instruction to customers running an emergency patch build is to move to a maintenance release [11].

What to watch

  • Whether GreyNoise or Blackpoint Cyber report data theft or ransomware from any of the 395 accesses.
  • Whether a fourth emergency patch follows the maintenance releases, which would mean the fix set is still moving.
  • Whether the activity moves off 45.142.193.132 onto fresh infrastructure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories