Critical 9.8 Actively Exploited

PaperCut MF/NG exploited, unauth config change (CVE-2026-81578) [PoC]

CVE-2026-81578

By Yazoul AI · automated

CVE-2026-81578: Actively exploited PaperCut MF/NG critical flaw lets unauthenticated attackers modify system config (CVSS 9.8). Update to latest version now.

Affected: Papercut Mf Papercut Ng

Actively exploited in the wild - CVE-2026-81578 is a critical improper access control vulnerability in PaperCut MF and PaperCut NG that lets unauthenticated remote attackers modify system configurations through the web management interface. Patched in the latest MF/NG releases; update immediately.

Overview

CVE-2026-81578 stems from an access validation gap in the web management interface of PaperCut MF and PaperCut NG print management software. Under specific conditions, unauthenticated HTTP requests targeting administrative functions can trigger backend actions before authentication and authorization checks complete. This race condition lets attackers modify system configuration settings without valid credentials.

The vulnerability carries a CVSS score of 9.8 (Critical). The vector is network-based with low attack complexity, requires no privileges, and needs no user interaction, making it straightforward to exploit remotely.

CISA has confirmed active exploitation in the wild and added this CVE to its Known Exploited Vulnerabilities catalog. Despite a low EPSS score of 0.4% probability of exploitation in the next 30 days, the confirmed in-the-wild activity demands immediate attention.

Impact

An attacker exploiting CVE-2026-81578 can:

  • Alter system configuration settings on the print server
  • Potentially disable security controls or redirect print jobs
  • Establish persistence for further attacks on the network

Because PaperCut often runs with elevated privileges on print servers, successful exploitation can also expose the broader network to lateral movement. Organizations running PaperCut in exposed or segmented environments should treat this as a network security incident, not just a print system issue.

Remediation

PaperCut has released patches for both MF and NG product lines. Take these steps:

  1. Update immediately - Apply the latest PaperCut MF and NG versions from the vendor’s official download portal. Check the vendor advisory for version-specific patch details.

  2. Restrict network access - Limit access to the web management interface to trusted administrative networks via firewall rules or VLAN segmentation.

  3. Audit configurations - Review recent configuration changes on PaperCut servers for signs of unauthorized modification, especially if the server was internet-facing.

  4. Monitor for indicators - Review access logs for suspicious requests targeting administrative endpoints from unexpected source IPs.

Security Insight

PaperCut joins a growing list of enterprise management platforms where authentication bypass flaws become the vector of choice for initial access. The pattern mirrors the 2023 PaperCut MF/NG RCE vulnerability (CVE-2023-27350), which was also actively exploited for ransomware deployment. That incident demonstrated that print management servers are not peripheral devices but high-value targets sitting on the network’s edge. The recurring theme is clear: vendors must treat access validation as a security boundary, not an optimization opportunity, and organizations must prioritize patching management interfaces alongside edge firewalls. More details on related incidents are available at security news and breach reports.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
yora1928/PaperCut-CVE-2026-81578-82078

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

★ 1
virologi-info/papercut-toolkit

#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained

★ 1

Showing 2 of 2 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Other Papercut Mf Vulnerabilities

View all Papercut Mf vulnerabilities →

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.