Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-81578

Published 2026-08-28
Updated 8 days ago
Vendor/s
PaperCut
Product/s
NG/MF
Version/s
* > 24.1.9
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-81578 is a critical 9.8 CVSS vulnerability in PaperCut NG/MF allowing unauthenticated remote configuration changes. Active exploitation reported.

CPE

PaperCut logo
PaperCut
Product Version Start Version End (excl.) Status
papercut_mf * 24.1.9 vulnerable
papercut_mf 25.0.2 25.0.12 vulnerable
papercut_mf 26.0.2 26.0.4 vulnerable
papercut_ng * 24.1.9 vulnerable
papercut_ng 25.0.2 25.0.12 vulnerable
papercut_ng 26.0.2 26.0.4 vulnerable

Related weakness (CWE)

CWE-305

Remediation plan

1

Apply official patches

Download and install the latest security updates from the PaperCut customer portal. Refer to the August 27, 2026, security advisory for specific hotfixes and installation instructions tailored to your specific deployment type.

2

Update affected systems

Ensure PaperCut MF/NG is updated to version 24.1.9, 25.0.12, 26.0.4, or later. Systems running versions prior to 24.1.9, or specific ranges in the 25.x (up to 25.0.11) and 26.x (up to 26.0.3) branches, are explicitly vulnerable.

3

Restrict access

Limit access to the PaperCut web management interface, specifically ports 9191 and 9192, to trusted internal IP addresses only. Implement a VPN or Zero Trust Network Access (ZTNA) solution to ensure the interface is never exposed to the public internet.

4

Monitor for exploitation

Review web server logs for unusual POST requests to administrative endpoints originating from unauthenticated or external IP addresses. Check for unauthorized changes to system settings, the creation of new administrative users, or unexpected backend configuration modifications.

Detection Guidance

"Monitor PaperCut application logs (server.log) and web server access logs for anomalous unauthenticated requests targeting administrative or setup-related endpoints. Look for high-frequency requests that attempt to bypass the standard login flow. Network-level detection should focus on identifying inbound traffic to ports 9191 and 9192 from unauthorized subnets. Organizations should also follow CISA’s Forensics Triage Requirements to scan for indicators of persistent configuration changes or unauthorized script execution within the PaperCut environment."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management