Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-82078 |
| Alert Source | CISA KEV - Active Exploitation |
| CVE Year | 2026 |
| Publication Date | 2026-08-31 |
| Vendor | PaperCut |
| Product | NG/MF |
| CVSS Score | N/A (Unknown) |
| EPSS Score | 0.5% (percentile: 38%) |
| CISA KEV | Yes - confirmed active exploitation |
| Ransomware | Not confirmed |
| Due Date | 2026-09-14 |
Vulnerability Description
PaperCut NG/MF contains an unsafe reflection vulnerability that lets an attacker manipulate the system configuration parameters and execute arbitrary Java bytecode present on the application classpath - in the security context of the PaperCut server process.
The vulnerability can be chained with CVE-2026-81578 (missing authentication for a critical function). The combination of the two gives an unauthenticated attacker a path from a configuration change to code execution.
CISA has added CVE-2026-82078 to the Known Exploited Vulnerabilities catalog, which means confirmed exploitation in real-world attacks. PaperCut servers have been targeted by ransomware campaigns before - in 2023 the CVE-2023-27350 vulnerability was exploited on a mass scale, among others by the Cl0p and LockBit operators.
Required Actions
-
Update PaperCut NG/MF to the version indicated in the vendor bulletin. The due date set by CISA is September 14, 2026 - binding for entities covered by BOD 22-01, and a realistic limit of the response window for everyone else.
-
Cut the administrative console off from the internet. Ports 9191 (HTTP) and 9192 (HTTPS) should not be publicly exposed - restrict access to the internal network or VPN.
-
Patch CVE-2026-81578 in parallel - both vulnerabilities are chained and updating one of them on its own does not close the attack path.
-
Review the server logs (
server/logs/) for unauthorized configuration changes, new scripts and unusual administrative operations from before the update date. -
Verify the privileges of the server process. If PaperCut runs as SYSTEM or root, code execution means immediate takeover of the host - restrict the service account to the minimum.
-
Treat the server as potentially compromised if it was exposed to the internet before the update, and carry out threat hunting rather than an update alone.
Who Is Affected?
Organizations using PaperCut NG or PaperCut MF to manage and account for printing. In Poland, this is a very widespread solution in public administration, higher education, hospitals, and in manufacturing and service companies with more than a few hundred workstations.
The greatest risk applies to installations where the PaperCut server is reachable from the internet (remote work, follow-me printing for branch offices). A print server tends to be treated as second-tier infrastructure, even though it has access to the user directory, to document queues and often to the domain controller.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
