A two-flaw vulnerability chain in PaperCut's print management software lets unauthenticated attackers take over servers used by schools and universities
Two vulnerabilities in PaperCut NG/MF, rated 8.8 and 9.4, let attackers bypass authentication and execute code without credentials. CISA added both to its Known Exploited Vulnerabilities catalog after confirming active attacks, per CISA, SecurityWeek and Rapid7.
Security researchers disclosed an unauthenticated remote-code-execution chain in PaperCut NG/MF, print management software widely deployed in schools, universities and public-sector offices. CVE-2026-81578 (CVSS 8.8) is a missing-authentication flaw that lets an attacker reach administrative functions without logging in; CVE-2026-82078 (CVSS 9.4) is an unsafe reflection flaw that lets the same attacker execute code on the server. PaperCut disclosed active exploitation on August 27, 2026 and shipped an emergency patch on August 28. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on August 31 and directed federal civilian agencies to remediate by September 14. Threat intelligence firm Defused reported attackers abusing the bypass to hijack PaperCut's user-lookup function and pull data from its embedded database. Sources: CISA, SecurityWeek, Rapid7.