PaperCut NG/MF Vulnerability CVE-2026-81578 Exploited in the Wild
- Severity
- CRITICAL
- Affected component
- papercut ng/mf (other)
- Patched version
- Not yet available
A critical vulnerability in PaperCut NG/MF, tracked as CVE-2026-81578, is being actively exploited in the wild. Users of PaperCut NG/MF are advised to upgrade to the latest version and apply the emergency fix released by the company.
What happened
The vulnerability, CVE-2026-81578, allows an unauthenticated remote attacker to modify certain system configurations. This can be chained with another vulnerability, CVE-2026-82078, to achieve remote code execution. Threat actors have been observed exploiting these vulnerabilities to steal credentials from schools and universities in the U.S. and Europe.
Post-exploitation activities include running discovery commands, creating privileged accounts, and delivering credential-harvesting tools. Inbound GET requests from specific IP addresses have been observed requesting sensitive files on compromised hosts.
What to do about it
- Upgrade to the latest version of PaperCut NG/MF.
- Apply the emergency fix released by PaperCut.
- Monitor for any unusual activity on your PaperCut servers.
- Consult the primary sources for the most up-to-date information and recommendations.
How 0Day would have caught this
papercut ng/mf is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using PaperCut NG/MF, you may be affected. No authoritative version range has been published yet.
What should I do right now?
Upgrade to the latest version of PaperCut NG/MF and apply the emergency fix released by the company.
Has this been exploited in the wild?
Yes, this vulnerability has been exploited in the wild.