๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Summary
PaperCut NG/MF has a vulnerability where attackers can skip authentication (the process of verifying a user's identity) to modify important system settings without permission. This flaw is actively being exploited and can be combined with another vulnerability (CVE-2026-82078) to cause additional damage.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions from PaperCut's security bulletin, following CISA's BOD 26-04 guidance for prioritizing security updates. For cloud services, follow BOD 26-04 guidance or discontinue use if mitigations are unavailable. Organizations must evaluate their systems' internet exposure and ensure patches are applied by the due date of 2026-09-14.
Vulnerability Details
EPSS: 0.4%
Yes
๐ฅ Actively Exploited
August 30, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81578
First tracked: August 31, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%