CISA Warns of Critical PaperCut NG/MF Exploited Vulnerabilities
Key Takeaways The U.S. CISA has issued an alert regarding two critical vulnerabilities in PaperCut NG/MF. These flaws, CVE-2026-81578 and CVE-2026-82078, are being actively exploited in the wild....
Key Takeaways
- The U.S. CISA has issued an alert regarding two critical vulnerabilities in PaperCut NG/MF.
- These flaws, CVE-2026-81578 and CVE-2026-82078, are being actively exploited in the wild.
- Attackers can chain these vulnerabilities to achieve unauthenticated remote code execution, compromising print management servers.
- The affected products are widely used in educational, enterprise, and government sectors.
- Immediate patching and mitigation are crucial, especially for internet-exposed systems.
CISA Flags Actively Exploited PaperCut Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning concerning two critical vulnerabilities impacting PaperCut NG and PaperCut MF. These flaws have been added to the agency’s CISA KEV Catalog, indicating that threat actors are actively leveraging them in real-world attacks against vulnerable systems.
Table Of Content
The identified vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, pose a significant risk. When exploited in tandem, they enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode. This malicious code runs with the same security context as the PaperCut server process, potentially granting attackers extensive control over the compromised system.
Widespread Impact on Critical Infrastructure
PaperCut NG and PaperCut MF are widely deployed print management solutions across various sectors, including educational institutions, large enterprises, government agencies, and managed service providers. Given their central role in managing print queues, user authentication, and document workflows, a compromised PaperCut server can serve as a critical entry point for attackers seeking to penetrate internal networks and exfiltrate sensitive data.
Details of the Vulnerabilities
CVE-2026-81578: Missing Authentication for Critical Function (CWE-306)
This vulnerability stems from a lack of proper authentication for a crucial function within PaperCut NG/MF. It allows a remote attacker to bypass authentication mechanisms and modify system configuration settings without providing valid credentials. This flaw alone grants unauthorized access to sensitive server controls.
CVE-2026-82078: Unsafe Reflection (CWE-470)
The second vulnerability involves unsafe reflection, categorized under CWE-470. This flaw permits an attacker to manipulate existing system configuration parameters to execute arbitrary Java bytecode already present within the application’s classpath. Successful exploitation means the attacker’s code runs with the same privileges as the PaperCut server process, potentially leading to full system compromise.
Chained Exploitation Leading to Remote Code Execution
The most severe threat arises when these two vulnerabilities are combined. An attacker can first exploit CVE-2026-81578 to alter server configurations without authentication. Following this, CVE-2026-82078 can be leveraged to invoke malicious behavior through unsafe reflection, ultimately leading to unauthenticated remote code execution. This chaining capability makes internet-exposed PaperCut management interfaces particularly vulnerable and a high-priority target for threat actors.
CISA Mandate and Remediation Deadline
CISA officially added both vulnerabilities to its KEV Catalog on August 31, 2026. For U.S. federal civilian executive branch agencies, a strict remediation deadline of September 14, 2026, has been set under BOD 22-01. While CISA’s entries currently list ransomware use as unknown for these specific flaws, their inclusion in the KEV Catalog explicitly signifies active exploitation in the wild.
What You Should Do
- Apply Patches Immediately: All organizations utilizing PaperCut NG or PaperCut MF should promptly consult vendor guidance and apply available security patches and updates without delay.
- Secure Internet-Facing Systems: Prioritize securing any PaperCut deployments exposed to the internet. Verify that administrative interfaces are not publicly accessible unless absolutely necessary, and implement strict access controls.
- Review Privileges: Assess the privileges under which the PaperCut service is running. Ensure it operates with the principle of least privilege to minimize the impact of a potential compromise.
- Monitor for Suspicious Activity: Proactively review PaperCut server logs, authentication event records, configuration change logs, and any unusual Java process activity for signs of unauthorized access or exploitation.
- Implement Network Segmentation: Isolate PaperCut servers on dedicated network segments to limit lateral movement possibilities in case of a breach.
- Discontinue Use if Unpatchable: If patches or effective mitigations cannot be applied, CISA advises organizations to follow applicable risk-based guidance for cloud services or discontinue the use of the affected product until a secure solution is available.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.