Critical Vulnerabilities in PaperCut NG and MF Exploited in the Wild
On August 27, 2026, PaperCut Software issued an urgent security advisory regarding active exploitation of vulnerabilities in its PaperCut NG and PaperCut MF products. The company confirmed incidents affecting customers and classified the situation as a security emergency. Initially, the vulnerabilities lacked CVE identifiers and detailed technical information. However, on August 28, PaperCut assigned CVE-2026-81578 and CVE-2026-82078 to the vulnerabilities that form the exploit chain.
PaperCut NG and MF are widely used print management platforms in enterprise and educational environments. Given that the PaperCut Application Server is accessible via the web, organizations with publicly exposed servers must prioritize remediation and restrict access.
The vulnerabilities are as follows:
| CVE ID | Description | CWE | CVSSv4 |
| CVE-2026-81578 | Authentication Bypass | CWE-306 Missing authentication for critical function. | 8.8 (High) |
| CVE-2026-82078 | Unsafe Dynamic Class Loading in Database Connector | CWE-470 Use of Externally-Controlled input to select classes or code (‘unsafe reflection’). | 9.4 (Critical) |
PaperCut’s advisory indicated that the vulnerabilities were reproduced with assistance from a university’s security team. Emergency patches for versions 24, 25, and 26 were released on August 28, 2026. Organizations using PaperCut NG or MF should apply these patches immediately, especially if their servers are accessible from the internet.
In light of previous incidents, such as the exploitation of CVE-2023-27350, the urgency for organizations to address these vulnerabilities is heightened. All versions of PaperCut NG and MF are considered potentially impacted, and immediate action is advised even in the absence of observed suspicious activity.
Mitigation Guidance
Organizations should prioritize the application of the emergency patches released by PaperCut. The vendor has also issued a second version of the emergency patch, which must be applied by any organization that previously installed the first version, as it does not provide adequate protection.
To further mitigate risks, administrators are advised to restrict web access to trusted IP addresses and implement firewall rules, network access controls, or reverse-proxy restrictions to prevent unauthorized access to PaperCut web interfaces. For the latest remediation guidance and indicators of compromise, refer to PaperCut’s security advisory.
For detection and forensic analysis, PaperCut has identified several preliminary artifacts that may indicate compromise, including alerts from security products related to the PaperCut Application Server and integrity issues with log files.
For more detailed information, please refer to the Rapid7 blog post.
Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.



