PaperCut NG and MF Vulnerabilities CVE-2026-81578 and CVE-2026-82078 Exploited in the Wild

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Critical Vulnerabilities in PaperCut NG and MF Exploited in the Wild

On August 27, 2026, PaperCut Software issued an urgent security advisory regarding active exploitation of vulnerabilities in its PaperCut NG and PaperCut MF products. The company confirmed incidents affecting customers and classified the situation as a security emergency. Initially, the vulnerabilities lacked CVE identifiers and detailed technical information. However, on August 28, PaperCut assigned CVE-2026-81578 and CVE-2026-82078 to the vulnerabilities that form the exploit chain.

PaperCut NG and MF are widely used print management platforms in enterprise and educational environments. Given that the PaperCut Application Server is accessible via the web, organizations with publicly exposed servers must prioritize remediation and restrict access.

The vulnerabilities are as follows:

CVE ID Description CWE CVSSv4
CVE-2026-81578 Authentication Bypass CWE-306 Missing authentication for critical function. 8.8 (High)
CVE-2026-82078 Unsafe Dynamic Class Loading in Database Connector CWE-470 Use of Externally-Controlled input to select classes or code (‘unsafe reflection’). 9.4 (Critical)

PaperCut’s advisory indicated that the vulnerabilities were reproduced with assistance from a university’s security team. Emergency patches for versions 24, 25, and 26 were released on August 28, 2026. Organizations using PaperCut NG or MF should apply these patches immediately, especially if their servers are accessible from the internet.

In light of previous incidents, such as the exploitation of CVE-2023-27350, the urgency for organizations to address these vulnerabilities is heightened. All versions of PaperCut NG and MF are considered potentially impacted, and immediate action is advised even in the absence of observed suspicious activity.

Mitigation Guidance

Organizations should prioritize the application of the emergency patches released by PaperCut. The vendor has also issued a second version of the emergency patch, which must be applied by any organization that previously installed the first version, as it does not provide adequate protection.

To further mitigate risks, administrators are advised to restrict web access to trusted IP addresses and implement firewall rules, network access controls, or reverse-proxy restrictions to prevent unauthorized access to PaperCut web interfaces. For the latest remediation guidance and indicators of compromise, refer to PaperCut’s security advisory.

For detection and forensic analysis, PaperCut has identified several preliminary artifacts that may indicate compromise, including alerts from security products related to the PaperCut Application Server and integrity issues with log files.

For more detailed information, please refer to the Rapid7 blog post.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Trump Administration Bans Foreign-Made Power Generation Equipment Over Cybersecurity Risks

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity and power, citing cybersecurity risks. The...

Iranian Hackers Shut Down UK Power Plant for Four Days in Unprecedented Attack

In a significant escalation of cyber warfare, Iranian hackers successfully shut down a British power plant for four days, marking a notable first for...

New Research Reveals Perturbation Probing Method to Assess LLM Safety Fragility

New Research Unveils Perturbation Probing Method to Assess LLM Safety Fragility Recent advancements in the field of large language models (LLMs) have raised critical questions...

US Treasury Sanctions Iranian Cyber Actors for Compromising Critical Infrastructure and Data Theft

The US Treasury has sanctioned several Iranian cyber actors linked to the Ministry of Intelligence and Security (MOIS), accusing them of compromising critical infrastructure...