CVE-2026-82078
Known exploited · CISA KEV
CISA federal remediation date Sep 11 · date passed
Vulnerabilities · 6h ago
PaperCut said on 27 August that attackers were already exploiting a vulnerability in PaperCut MF and PaperCut NG, and it published indicators of compromise without a patch. watchTowr later said the issue was not a single bug but a pre-authentication remote-code-execution chain with patch bypasses, tracked by PaperCut as CVE-2026-82077, CVE-2026-82078, and CVE-2026-81578.
The mechanism matters because the first fix covered one route into the same bad behavior, while a second route still reached the vulnerable code path. In plain terms, the patch closed a doorway, not the room, so a single CVE label did not mean the whole product was safe.
For admins running PaperCut as an internal print appliance, the exposure is now product-wide until a fixed version lands; until then, the vendor advisory and hunt data are the only cleanup points. Any environment that treats one patched finding as the end of the story risks leaving another exploitable path in place.
Known exploited · CISA KEV
CISA federal remediation date Sep 11 · date passed
Known exploited · CISA KEV
CISA federal remediation date Sep 11 · date passed
EPSS 0.7% (53rd percentile).
1 source covering this story
There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into singular CVE IDs.
Part of the PlainSec briefing for 2026-10-09