CVE-2026-82078 is a critical 9.1 RCE vulnerability in PaperCut NG/MF. Actively exploited, it requires immediate patching to versions 24.1.9, 25.0.12, or 26.0.4.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| papercut_mf | * | 24.1.9 | vulnerable |
| papercut_mf | 25.0.2 | 25.0.12 | vulnerable |
| papercut_mf | 26.0.2 | 26.0.4 | vulnerable |
| papercut_ng | * | 24.1.9 | vulnerable |
| papercut_ng | 25.0.2 | 25.0.12 | vulnerable |
| papercut_ng | 26.0.2 | 26.0.4 | vulnerable |
Immediately download and apply the security patches released by PaperCut. Refer to the August 2026 security bulletin for specific instructions on applying the fix to your PaperCut NG or MF environment and ensure the server service is restarted to finalize the update.
Upgrade your PaperCut installation to version 24.1.9, 25.0.12, 26.0.4, or a more recent release. These versions contain the necessary validation logic to prevent unauthorized dynamic class loading through database connection utilities.
Harden the security of the PaperCut administration interface by restricting access to a dedicated management VLAN or specific authorized IP addresses. Implementing multi-factor authentication (MFA) for administrative accounts can further mitigate the risk of configuration manipulation.
Review application and system logs for unauthorized changes to database configuration parameters or driver names. Use endpoint detection and response (EDR) solutions to monitor the PaperCut server process for the execution of unexpected child processes or suspicious Java class loading events.
"Detection should focus on identifying unauthorized changes to PaperCut's database configuration files and logs. Monitor for modifications to database driver settings or connection strings that do not align with known administrative actions. Search for log entries indicating the initialization of unknown Java classes. Additionally, use network monitoring to detect unusual outbound connections from the PaperCut server, which could signify a reverse shell or communication with a malicious command-and-control server following successful exploitation."
Experience superior visibility and a simpler approach to cyber risk management