// CVE

CVE-2026-82078

Critical 9.4 Exploited (KEV)

PaperCut PaperCut MF/NG

9.4CVSS
61%EPSS
YesCISA KEV

Summary

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an…

Published: 2026-08-28 · In KEV since: 2026-08-31

Analysis

🔴 Critical — actively exploited

Weakness: CWE-470.

How it's exploited: Exploitable over the network (internet-reachable), with high privileges, no user interaction, and with low complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →

← Back to the Threat Radar

Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.