Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-82078

Published 2026-08-28
Updated 9 days ago
Vendor/s
PaperCut
Product/s
NG/MF
Version/s
* > 24.1.9
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.1
/ 10
Critical
Severity Details
Base score
9.1 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-82078 is a critical 9.1 RCE vulnerability in PaperCut NG/MF. Actively exploited, it requires immediate patching to versions 24.1.9, 25.0.12, or 26.0.4.

CPE

PaperCut logo
PaperCut
Product Version Start Version End (excl.) Status
papercut_mf * 24.1.9 vulnerable
papercut_mf 25.0.2 25.0.12 vulnerable
papercut_mf 26.0.2 26.0.4 vulnerable
papercut_ng * 24.1.9 vulnerable
papercut_ng 25.0.2 25.0.12 vulnerable
papercut_ng 26.0.2 26.0.4 vulnerable

Related weakness (CWE)

CWE-470

Remediation plan

1

Apply official patches

Immediately download and apply the security patches released by PaperCut. Refer to the August 2026 security bulletin for specific instructions on applying the fix to your PaperCut NG or MF environment and ensure the server service is restarted to finalize the update.

2

Update affected systems

Upgrade your PaperCut installation to version 24.1.9, 25.0.12, 26.0.4, or a more recent release. These versions contain the necessary validation logic to prevent unauthorized dynamic class loading through database connection utilities.

3

Restrict access

Harden the security of the PaperCut administration interface by restricting access to a dedicated management VLAN or specific authorized IP addresses. Implementing multi-factor authentication (MFA) for administrative accounts can further mitigate the risk of configuration manipulation.

4

Monitor for exploitation

Review application and system logs for unauthorized changes to database configuration parameters or driver names. Use endpoint detection and response (EDR) solutions to monitor the PaperCut server process for the execution of unexpected child processes or suspicious Java class loading events.

Detection Guidance

"Detection should focus on identifying unauthorized changes to PaperCut's database configuration files and logs. Monitor for modifications to database driver settings or connection strings that do not align with known administrative actions. Search for log entries indicating the initialization of unknown Java classes. Additionally, use network monitoring to detect unusual outbound connections from the PaperCut server, which could signify a reverse shell or communication with a malicious command-and-control server following successful exploitation."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management