PaperCut security advisory (AV26-858) – Update 2
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 2 of 2 flaws named
- Flaws named
- CVE-2026-81578CVE-2026-82078
- Vendors and products
- PaperCut
- Industries
- Government
- Reported by
- 1 outlet
As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products:
- PaperCut MF
- Prior to v24 Emergency Patch Release 2
- Prior to v25 Emergency Patch Release 2
- Prior to v26 Emergency Patch Release 2
- PaperCut NG
- Prior to v24 Emergency Patch Release 2
- Prior to v25 Emergency Patch Release 2
- Prior to v26 Emergency Patch Release 2
Update 1
Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild.
Update 2
On August 31, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-815789.8Critical
PaperCut NG/MF
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
Used in attacksAdded to CISA's list 2026-08-31 · Patch or advisory available
Full record → - CVE-2026-820789.1Critical
PaperCut NG/MF
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
Used in attacksAdded to CISA's list 2026-08-31 · Patch or advisory available
Full record →
Coverage
One outlet has carried this so far.
2026-08-31 16:00 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited