CRITICAL: PaperCut Zero-Days Exploited to Breach 395 Organizations
PaperCut has shipped maintenance releases 26.0.5, 25.0.13, and 24.1.10 to replace three rounds of emergency patches for CVE-2026-81578 and CVE-2026-82078, two actively exploited flaws that chain into preauthentication remote code execution. Researchers tracked a campaign that compromised more than 440 instances at 395 organizations across 48 countries, reaching domain admin at one school in seven minutes.