// CVE

CVE-2026-81578

High 8.8 Exploited (KEV)

PaperCut PaperCut MF/NG

8.8CVSS
85%EPSS
YesCISA KEV

Summary

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior…

Published: 2026-08-28 · In KEV since: 2026-08-31

Analysis

🔴 Critical — actively exploited

Weakness: CWE-305.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, and with low complexity.

⚠️ Critical combo: remote, unauthenticated and no interaction → trivial to automate.

Impact: Confidentiality partial · Integrity high · Availability partial.

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →

← Back to the Threat Radar

Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.