CVE-2026-81578 is a critical 9.8 CVSS vulnerability in PaperCut NG/MF allowing unauthenticated remote configuration changes. Active exploitation reported.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| papercut_mf | * | 24.1.9 | vulnerable |
| papercut_mf | 25.0.2 | 25.0.12 | vulnerable |
| papercut_mf | 26.0.2 | 26.0.4 | vulnerable |
| papercut_ng | * | 24.1.9 | vulnerable |
| papercut_ng | 25.0.2 | 25.0.12 | vulnerable |
| papercut_ng | 26.0.2 | 26.0.4 | vulnerable |
Download and install the latest security updates from the PaperCut customer portal. Refer to the August 27, 2026, security advisory for specific hotfixes and installation instructions tailored to your specific deployment type.
Ensure PaperCut MF/NG is updated to version 24.1.9, 25.0.12, 26.0.4, or later. Systems running versions prior to 24.1.9, or specific ranges in the 25.x (up to 25.0.11) and 26.x (up to 26.0.3) branches, are explicitly vulnerable.
Limit access to the PaperCut web management interface, specifically ports 9191 and 9192, to trusted internal IP addresses only. Implement a VPN or Zero Trust Network Access (ZTNA) solution to ensure the interface is never exposed to the public internet.
Review web server logs for unusual POST requests to administrative endpoints originating from unauthenticated or external IP addresses. Check for unauthorized changes to system settings, the creation of new administrative users, or unexpected backend configuration modifications.
"Monitor PaperCut application logs (server.log) and web server access logs for anomalous unauthenticated requests targeting administrative or setup-related endpoints. Look for high-frequency requests that attempt to bypass the standard login flow. Network-level detection should focus on identifying inbound traffic to ports 9191 and 9192 from unauthorized subnets. Organizations should also follow CISA’s Forensics Triage Requirements to scan for indicators of persistent configuration changes or unauthorized script execution within the PaperCut environment."
Experience superior visibility and a simpler approach to cyber risk management