CVE-2026-82078 – PaperCut MF/NG

CVSS 9.1 CRITICAL Zero Day – Immediate Deployment

“Active exploitation can turn exposed PaperCut administration paths into configuration compromise and server-side code execution.”

PaperCut MF and PaperCut NG are affected by two actively exploited vulnerabilities. CVE-2026-81578 allows unauthenticated remote requests to reach administrative backend actions before access checks complete, enabling unauthorized modification of system configuration. The CVSS score is 8.8, which is High severity.

CVE-2026-82078 is a Critical unsafe dynamic class loading flaw. An attacker able to manipulate configuration parameters can cause PaperCut to load attacker-selected Java classes from the application classpath and execute bytecode under the PaperCut server process. The CVSS score is 9.4, which is Critical severity. Active exploitation is confirmed for both vulnerabilities.

Key Details

Affected Product
Papercut Papercut Mf
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-470
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.