PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF
CVE-2026-81578 and CVE-2026-82078 may enable configuration modification and code execution on PaperCut NG and PaperCut MF
Summary
CVE-2026-81578 and CVE-2026-82078 may enable configuration modification and code execution on PaperCut NG and PaperCut MF
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-81578 and CVE-2026-82078
Active exploitation of CVE-2026-81578 and CVE-2026-82078 has been reported. PaperCut has confirmed customer incidents and released emergency patches, which includes urging all customers to install Release 2, as it contains additional hardening measures and protections.
Their guidance recommends immediate action to restrict exposure of internet-accessible PaperCut servers. PaperCut states:
"If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).
Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity."
The NHS England National CSOC assess continued exploitation of these vulnerabilities as highly likely.
Introduction
PaperCut has released emergency security updates to address two vulnerabilities affecting PaperCut MF and PaperCut NG. Successful exploitation could enable unauthorised modification of system configuration and may ultimately facilitate arbitrary code execution on affected servers.
- CVE-2026-82078 – Unsafe Dynamic Class Loading vulnerability that could lead to the execution of arbitrary Java bytecode – CVSSv4: 9.4
- CVE-2026-81578 – Improper Access Control vulnerability that could lead to an authenticated remote attacker to modify system configurations – CVSSv4: 8.8
Remediation advice
Affected organisations are strongly encouraged to review the PaperCut NG/MF Security Bulletin (27 Aug 2026) and apply the latest Emergency Patch Release 2 as soon as possible.
The Papercut team released indicators of compromise and investigation guidance in the security bulletin.
Where immediate patching is not possible, organisations should restrict access to PaperCut Application Server web interfaces to trusted IP addresses only and ensure any public internet exposure is removed.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 28 August 2026 3:05 pm