Search
Find merged stories by title or summary.
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-81578 (CVSS score of 8.8) PaperCut NG/MF Missing Authentication for Critical Function Vulnerability • CVE-2026-82078 (CVSS score of 9.4) PaperCut NG/MF Unsafe Reflection Vulnerability PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, is being actively exploited against real customers.
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek .
CISA Warns of Two PaperCut NG/MF Vulnerabilities Actively Exploited in Attacks
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG and PaperCut MF to its Known Exploited Vulnerabilities (KEV) Catalog, warning that threat actors are actively exploiting the flaws in real-world attacks. The flaws, addressing critical PaperCut vulnerabilities tracked as CVE-2026-81578 and CVE-2026-82078 , can be chained to enable unauthenticated attackers to alter server configurations and execute malicious Java bytecode under the security context of the PaperCut server process. CISA Warns of PaperCut NG/MF Vulnerabilities PaperCut NG and PaperCut MF are widely used print-management platforms deployed by schools, enterprises, government agencies, and managed service providers.
Metasploit Exploit Targets Actively Exploited PaperCut NG/MF Zero-Day RCE Chain
A new Metasploit Framework module is poised to make a recently disclosed, actively exploited PaperCut NG and MF zero-day chain more accessible. Rapid7 contributor Stephen Fewer submitted pull request #21842 for CVE-2026-81578 and CVE-2026-82078, flaws that combine authentication bypass with remote code execution. The development arrives days after PaperCut confirmed customer incidents. Every PaperCut NG and MF version may be affected. Metasploit Exploit Targets Actively Exploited Emergency Patch Release 2 is available for supported 24. x, 25. x, and 26. x releases, and administrators who deployed the first emergency patch must install it because it adds protections beyond the original fix.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CVE-2026-82078 - PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
CVE-2026-81578 - PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain. CVE ID Description CWE CVSSv4 CVE-2026-81578
You've reached the end of current stories for this search.
