Skip to content
CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF

CC-4838 - PaperCut Releases Emergency Security Updates for Critical Vulnerabilities in PaperCut NG/MF

Digital.Nhs.Uk [email protected] (NHS Digital) August 28, 2026

CVE-2026-81578 and CVE-2026-82078 may enable configuration modification and code execution on PaperCut NG and PaperCut MF

CVE-2026-81578 and CVE-2026-82078 may enable configuration modification and code execution on PaperCut NG and PaperCut MF

The following platforms are known to be affected:

PaperCut MF/NG Application Servers and Site Servers

Note: The recommended path for all customers prior to PaperCut NG/MF v24 is to upgrade to the latest version.

Exploitation of CVE-2026-81578 and CVE-2026-82078

Active exploitation of CVE-2026-81578 and CVE-2026-82078 has been reported. PaperCut has confirmed customer incidents and released emergency patches, which includes urging all customers to install Release 2, as it contains additional hardening measures and protections.

Their guidance recommends immediate action to restrict exposure of internet-accessible PaperCut servers. PaperCut states:

"If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).

Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity."

The NHS England National CSOC assess continued exploitation of these vulnerabilities as highly likely.

PaperCut has released emergency security updates to address two vulnerabilities affecting PaperCut MF and PaperCut NG. Successful exploitation could enable unauthorised modification of system configuration and may ultimately facilitate arbitrary code execution on affected servers.

Affected organisations are strongly encouraged to review the PaperCut NG/MF Security Bulletin (27 Aug 2026) and apply the latest Emergency Patch Release 2 as soon as possible.

The Papercut team released indicators of compromise and investigation guidance in the security bulletin.

Where immediate patching is not possible, organisations should restrict access to PaperCut Application Server web interfaces to trusted IP addresses only and ensure any public internet exposure is removed.

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Last edited: 28 August 2026 3:05 pm