Skip to content
Security Alerts

CVE-2026-82078: Actively Exploited Vulnerability in PaperCut NG/MF (CISA KEV)

PaperCut NG/MF contains an unsafe reflection vulnerability that allows the system configuration to be manipulated and arbitrary Java bytecode from the application classpath to be executed. The vulnerability is being actively exploited...

Summary

ParameterValue
CVE IDCVE-2026-82078
Alert SourceCISA KEV - Active Exploitation
CVE Year2026
Publication Date2026-08-31
VendorPaperCut
ProductNG/MF
CVSS ScoreN/A (Unknown)
EPSS Score0.5% (percentile: 38%)
CISA KEVYes - confirmed active exploitation
RansomwareNot confirmed
Due Date2026-09-14

Vulnerability Description

PaperCut NG/MF contains an unsafe reflection vulnerability that lets an attacker manipulate the system configuration parameters and execute arbitrary Java bytecode present on the application classpath - in the security context of the PaperCut server process.

The vulnerability can be chained with CVE-2026-81578 (missing authentication for a critical function). The combination of the two gives an unauthenticated attacker a path from a configuration change to code execution.

CISA has added CVE-2026-82078 to the Known Exploited Vulnerabilities catalog, which means confirmed exploitation in real-world attacks. PaperCut servers have been targeted by ransomware campaigns before - in 2023 the CVE-2023-27350 vulnerability was exploited on a mass scale, among others by the Cl0p and LockBit operators.

Required Actions

  • Update PaperCut NG/MF to the version indicated in the vendor bulletin. The due date set by CISA is September 14, 2026 - binding for entities covered by BOD 22-01, and a realistic limit of the response window for everyone else.

  • Cut the administrative console off from the internet. Ports 9191 (HTTP) and 9192 (HTTPS) should not be publicly exposed - restrict access to the internal network or VPN.

  • Patch CVE-2026-81578 in parallel - both vulnerabilities are chained and updating one of them on its own does not close the attack path.

  • Review the server logs (server/logs/) for unauthorized configuration changes, new scripts and unusual administrative operations from before the update date.

  • Verify the privileges of the server process. If PaperCut runs as SYSTEM or root, code execution means immediate takeover of the host - restrict the service account to the minimum.

  • Treat the server as potentially compromised if it was exposed to the internet before the update, and carry out threat hunting rather than an update alone.

Who Is Affected?

Organizations using PaperCut NG or PaperCut MF to manage and account for printing. In Poland, this is a very widespread solution in public administration, higher education, hospitals, and in manufacturing and service companies with more than a few hundred workstations.

The greatest risk applies to installations where the PaperCut server is reachable from the internet (remote work, follow-me printing for branch offices). A print server tends to be treated as second-tier infrastructure, even though it has access to the user directory, to document queues and often to the domain controller.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist