Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The PaperCut NG/MF Vulnerability: A Wake-Up Call for Organizations to Address Critical Exploited Flaws


U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog, warning of a critical vulnerability that can be exploited by attackers to execute arbitrary code on servers. Organizations are urged to patch their installations immediately to prevent potential attacks.

  • Two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, were added to the Known Exploited Vulnerabilities (KEV) catalog by CISA, posing significant risks to PaperCut installations.
  • PaperCut NG/MF's flaws allow attackers to execute arbitrary code, potentially leading to elevated privileges and further malicious activities.
  • The vulnerabilities are due to a simple authorization mistake in PaperCut and the loading of unsafe Java classes in the software's database utilities.
  • 47% of PaperCut installations are still running version 23 or earlier, with no available patch, posing a significant concern.
  • Organizations must take immediate action to patch their PaperCut installations, particularly those running version 23 or earlier.



  • The recent addition of PaperCut NG/MF flaws to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) serves as a stark reminder to organizations to prioritize their cybersecurity posture. The two identified vulnerabilities, CVE-2026-81578 and CVE-2026-82078, pose significant risks to PaperCut installations, particularly those running version 23 or earlier, which lack a patch.

    PaperCut NG/MF is a widely used print management software in schools, hospitals, and offices globally. The flaws discovered in the software enable attackers to execute arbitrary code on the server, potentially leading to elevated privileges and further malicious activities. The vulnerability starts with a simple authorization mistake in PaperCut, allowing an attacker to send a specially crafted request that makes the server display one page while actually running an action from another page. This can lead to unauthorized access to the server's configuration.

    The second identified flaw, CVE-2026-82078, relates to the loading of unsafe Java classes in PaperCut's database utilities. This can allow an attacker to run arbitrary Java code on the server, further exacerbating the risk. The attackers observed in the incident did not exhibit any evidence of deeper persistence, secondary malware, or follow-up command-and-control traffic, but the forensic trail left behind by the attackers is genuinely useful for defenders.

    The patching process for PaperCut is more complicated than a simple update, as the company released an emergency patch followed by another update less than 24 hours later after additional testing. The timing is critical, as the second confirmed attack targeted a server running version 24, before the fix for that version was available.

    The 47% of PaperCut installations still running version 23 or earlier pose a significant concern, as there is currently no patch for these versions. The U.S. CISA has ordered federal agencies to fix the flaws by September 14. Experts recommend that private organizations review the catalog and address the vulnerabilities in their infrastructure.

    In light of this vulnerability, organizations must take immediate action to address the identified flaws. This includes ensuring that all PaperCut installations are patched, particularly those running version 23 or earlier. The incident highlights the importance of staying up-to-date with the latest security patches and the need for a proactive approach to cybersecurity.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-PaperCut-NGMF-Vulnerability-A-Wake-Up-Call-for-Organizations-to-Address-Critical-Exploited-Flaws-ehn.shtml

  • https://securityaffairs.com/198200/security/u-s-cisa-adds-papercut-ng-mf-flaws-to-its-known-exploited-vulnerabilities-catalog.html

  • https://cybersecuritynews.com/papercut-ng-mf-vulnerabilities-exploited/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81578

  • https://www.cvedetails.com/cve/CVE-2026-81578/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-82078

  • https://www.cvedetails.com/cve/CVE-2026-82078/


  • Published: Tue Sep 1 04:33:16 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us