PaperCut security advisory (AV26-858) – Update 2

Used in attacksCriticalCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Critical
Used in attacks
Yes, 2 of 2 flaws named
Vendors and products
PaperCut
Industries
Government
Reported by
1 outlet

As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products:

  • PaperCut MF
    • Prior to v24 Emergency Patch Release 2
    • Prior to v25 Emergency Patch Release 2
    • Prior to v26 Emergency Patch Release 2
  • PaperCut NG
    • Prior to v24 Emergency Patch Release 2
    • Prior to v25 Emergency Patch Release 2
    • Prior to v26 Emergency Patch Release 2

Update 1

Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild.

Update 2

On August 31, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-815789.8Critical

    PaperCut NG/MF

    PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

    Used in attacks

    Added to CISA's list 2026-08-31 · Patch or advisory available

    Full record →
  • CVE-2026-820789.1Critical

    PaperCut NG/MF

    PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

    Used in attacks

    Added to CISA's list 2026-08-31 · Patch or advisory available

    Full record →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-08-31 16:00 UTC

Related stories