Skip to content
Active Exploitation of PaperCut Vulnerabilities CVE-2026-81578 and CVE-2026-82078

Active Exploitation of PaperCut Vulnerabilities CVE-2026-81578 and CVE-2026-82078

First seen 29 Sep 2026, 03:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 05:09 UTC
  • •CVE-2026-81578 allows unauthorized admin actions via an access control bypass.
  • •CVE-2026-82078 enables arbitrary code execution through unsafe dynamic class loading.
  • •Both vulnerabilities are actively exploited, with CISA listing them on August 31, 2026.

Two critical vulnerabilities in PaperCut MF/NG have been identified, CVE-2026-81578 and CVE-2026-82078, both published on August 28, 2026. CVE-2026-81578 allows unauthenticated attackers to exploit an access control bypass via crafted POST requests, enabling administrative actions. CVE-2026-82078 involves unsafe dynamic class loading, which can lead to arbitrary Java bytecode execution on the server. Both vulnerabilities were added to the CISA KEV list on August 31, 2026, indicating active exploitation in the wild. Attackers are targeting the Tapestry web interface of PaperCut systems, affecting organizations relying on these applications. The current status of these vulnerabilities is critical, with ongoing exploitation reported. Security professionals are urged to take immediate action to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-28
CVE-2026-81578 and CVE-2026-82078 published
Two critical vulnerabilities in PaperCut MF/NG were disclosed, affecting user authentication and code execution.
viz.greynoise.io
2026-08-31
CVE-2026-81578 and CVE-2026-82078 added to CISA KEV
Both vulnerabilities were recognized for active exploitation, prompting immediate attention from security teams.
viz.greynoise.io

More articles in this cluster (2)

Following this threat?

Track CVE-2026-81578 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed