LIVE · cybersecurity feed
Live wire
vendor2 exploited in the wild

Papercut

2 CVEs published in the last four months and 6 stories. Exploited flaws first.

Critical2
High0
Medium0
Exploited (KEV)2

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-81578exploited9.8criticalpapercut mfAn improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.8d ago
CVE-2026-82078exploited9.1criticalpapercut mfAn unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and Paper8d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-81578exploited9.8criticalpapercut mfAn improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.8d ago
CVE-2026-82078exploited9.1criticalpapercut mfAn unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and Paper8d ago

Filter the full tracker by Papercut

Our coverage of Papercut

CVE-2026-81578

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

vulnerabilityhigh

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evide

CVE-2026-82078critical

PaperCut releases second emergency patch for exploited flaws

PaperCut has issued a second emergency patch for its NG and MF print management software to address two critical vulnerabilities. These flaws, CVE-2026-82078 and CVE-2026-81578, were found to be bypassable by initial fixes and allow attackers to achieve authentication bypass and remote code execution. The company urges all customers to install the latest patch, even if they applied the first one, and to implement network access controls as a precautionary measure.

vulnerability

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

vulnerability

PaperCut warns of hackers using printer management software flaw in attacks

PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.