Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-82078

Published 2026-08-28

Updated 9 days ago

Vendor/s

PaperCut

Product/s

NG/MF

Version/s

\* > 24.1.9

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

9.1

/ 10

Critical

Severity Details

Base score

9.1 Critical

Attack vector

Network

Attack complexity

Low

Privileges required

High

User interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-82078 is a critical 9.1 RCE vulnerability in PaperCut NG/MF. Actively exploited, it requires immediate patching to versions 24.1.9, 25.0.12, or 26.0.4.

## Why this matters

"CVE-2026-82078 is a critical vulnerability with a CVSS score of 9.1 affecting PaperCut NG and MF, which are widely used in enterprise print management. This flaw involves unsafe dynamic class loading, allowing remote attackers to execute arbitrary Java bytecode under the security context of the PaperCut server process. Significantly, this vulnerability is listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning it is being actively leveraged by threat actors. Organizations at risk face total system compromise, potentially leading to data exfiltration or lateral movement within the network if management interfaces are exposed or administrative credentials are compromised."

## CPE

PaperCut

| Product      | Version Start | Version End (excl.) | Status     |
| ------------ | ------------- | ------------------- | ---------- |
| papercut\_mf | \*            | 24.1.9              | vulnerable |
| papercut\_mf | 25.0.2        | 25.0.12             | vulnerable |
| papercut\_mf | 26.0.2        | 26.0.4              | vulnerable |
| papercut\_ng | \*            | 24.1.9              | vulnerable |
| papercut\_ng | 25.0.2        | 25.0.12             | vulnerable |
| papercut\_ng | 26.0.2        | 26.0.4              | vulnerable |

## Related weakness (CWE)

CWE-470

## Remediation plan

1

### Apply official patches

Immediately download and apply the security patches released by PaperCut. Refer to the August 2026 security bulletin for specific instructions on applying the fix to your PaperCut NG or MF environment and ensure the server service is restarted to finalize the update.

2

### Update affected systems

Upgrade your PaperCut installation to version 24.1.9, 25.0.12, 26.0.4, or a more recent release. These versions contain the necessary validation logic to prevent unauthorized dynamic class loading through database connection utilities.

3

### Restrict access

Harden the security of the PaperCut administration interface by restricting access to a dedicated management VLAN or specific authorized IP addresses. Implementing multi-factor authentication (MFA) for administrative accounts can further mitigate the risk of configuration manipulation.

4

### Monitor for exploitation

Review application and system logs for unauthorized changes to database configuration parameters or driver names. Use endpoint detection and response (EDR) solutions to monitor the PaperCut server process for the execution of unexpected child processes or suspicious Java class loading events.

## Detection Guidance

"Detection should focus on identifying unauthorized changes to PaperCut's database configuration files and logs. Monitor for modifications to database driver settings or connection strings that do not align with known administrative actions. Search for log entries indicating the initialization of unknown Java classes. Additionally, use network monitoring to detect unusual outbound connections from the PaperCut server, which could signify a reverse shell or communication with a malicious command-and-control server following successful exploitation."

## References

[https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ Patch Vendor Advisory ](https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/)[https://github.com/rapid7/metasploit-framework/pull/21842 Issue Tracking Patch ](https://github.com/rapid7/metasploit-framework/pull/21842)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-82078 Patch Third Party Advisory US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
