Advisory Date: August 28, 2026
Last Updated: August 31, 2026
Recent vulnerabilities have been identified in PaperCut products, specifically affecting versions of PaperCut MF and PaperCut NG. As of August 27, 2026, the following versions are impacted:
- PaperCut MF
- Prior to v24 Emergency Patch Release 2
- Prior to v25 Emergency Patch Release 2
- Prior to v26 Emergency Patch Release 2
- PaperCut NG
- Prior to v24 Emergency Patch Release 2
- Prior to v25 Emergency Patch Release 2
- Prior to v26 Emergency Patch Release 2
Exploitation Status
Open-source intelligence has indicated that vulnerabilities identified as CVE-2026-81578 and CVE-2026-82078 are currently being exploited in the wild. This raises significant concerns for organizations using the affected versions of PaperCut software.
Official Response and Recommendations
On August 31, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added both CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database. This inclusion highlights the urgency for users and administrators to take immediate action.
The Cyber Centre advises all users of PaperCut MF and PaperCut NG to review the advisory and apply any necessary updates as they become available. It is crucial to ensure that systems are running the latest versions to mitigate the risk of exploitation.
For further details and updates, please refer to the official advisory from the Cyber Centre: Cyber.gc.ca.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



