The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding two significant vulnerabilities in PaperCut NG and PaperCut MF systems. These vulnerabilities, now part of CISA’s Known Exploited Vulnerabilities Catalog, are currently being exploited by cybercriminals in active attacks, necessitating immediate attention and remediation from organizations using these platforms.
Details of the PaperCut Vulnerabilities
The identified vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, present critical security issues that can be leveraged by unauthenticated attackers. These flaws allow changes to server configurations and the execution of harmful Java bytecode within the PaperCut server’s security context. This makes them particularly dangerous for institutions relying on these print management solutions.
PaperCut NG and MF are extensively utilized across various sectors including education, corporate, and government for managing printing services, user authentication, and document workflows. The central role of these systems in organizational operations heightens the risk of network exposure and unauthorized access if they are compromised.
Exploit Mechanism and Risks
CVE-2026-81578 is identified as a missing authentication issue that affects a critical function, allowing remote attackers to modify system configurations without needing valid credentials. This vulnerability is categorized under CWE-306 for missing authentication for vital functions.
The second vulnerability, CVE-2026-82078, involves unsafe reflection, classified as CWE-470. It allows attackers to manipulate system parameters and execute arbitrary Java bytecode from the existing application classpath. When these vulnerabilities are exploited in combination, they could lead to severe remote compromises of vulnerable systems, especially those with interfaces exposed to the internet.
Recommended Actions and Future Outlook
CISA has set a remediation deadline of September 14, 2026, for federal agencies to address these vulnerabilities. Organizations using PaperCut NG or MF should follow vendor guidelines and implement available security patches promptly. It is crucial for security teams to focus on systems that are internet-facing, ensuring that administrative interfaces are not freely accessible from public networks and that the PaperCut service is running with appropriate privileges.
In scenarios where applying patches is not feasible, organizations are advised to adhere to risk-based guidance concerning cloud services or consider discontinuing the use of the affected software. Administrators should also be vigilant by monitoring PaperCut server logs and configuration changes for any signs of unauthorized activity.
While CISA does not mandate forensic analysis for these vulnerabilities under BOD 26-04, the potential for chained exploitation necessitates proactive investigation, particularly in environments with externally accessible PaperCut instances. Staying ahead of potential threats is essential to maintaining secure operations.
