๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability
Summary
PaperCut NG/MF has an unsafe reflection vulnerability (a flaw where attackers can use programming reflection to access and execute code they shouldn't be able to reach) that lets attackers run malicious Java bytecode (compiled Java instructions) with the same permissions as the PaperCut server itself. This vulnerability is actively being exploited by real attackers and can be combined with another vulnerability (CVE-2026-81578) to cause more damage.
Solution / Mitigation
Apply mitigations according to PaperCut vendor instructions while following CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow applicable BOD 26-04 guidance or stop using the product if mitigations are unavailable. Evaluate each system's internet exposure and ensure compliance with BOD 26-04 patching guidelines by the due date of 2026-09-14. See PaperCut's security bulletin at https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 for specific vendor instructions.
Vulnerability Details
EPSS: 0.5%
Yes
๐ฅ Actively Exploited
August 30, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82078
First tracked: August 31, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%