Vulnerabilities · 6h ago

PaperCut exploitation stays open after advisory

PaperCut said on 27 August that attackers were already exploiting a vulnerability in PaperCut MF and PaperCut NG, and it published indicators of compromise without a patch. watchTowr later said the issue was not a single bug but a pre-authentication remote-code-execution chain with patch bypasses, tracked by PaperCut as CVE-2026-82077, CVE-2026-82078, and CVE-2026-81578.

The mechanism matters because the first fix covered one route into the same bad behavior, while a second route still reached the vulnerable code path. In plain terms, the patch closed a doorway, not the room, so a single CVE label did not mean the whole product was safe.

For admins running PaperCut as an internal print appliance, the exposure is now product-wide until a fixed version lands; until then, the vendor advisory and hunt data are the only cleanup points. Any environment that treats one patched finding as the end of the story risks leaving another exploitable path in place.

CVE-2026-82078

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Sep 11 · date passed

CVE-2026-81578

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Sep 11 · date passed

CVE-2026-82077

NVD KEV

EPSS 0.7% (53rd percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-09

Editions

Related stories