PaperCut Security Advisory: What You Need to Know 

PaperCut Security Advisory: What You Need to Know 

PaperCut Security Advisory Thumbnail

PaperCut has issued an urgent security advisory regarding active exploitation of vulnerabilities affecting PaperCut NG and PaperCut MF installations.  

Find out who is affected, what it means, and the immediate next steps you can take to protect your environment and reduce your risk: 

What’s Happening? 

PaperCut announced on August 27, 2026, that it was investigating active attacks targeting vulnerabilities in PaperCut NG and PaperCut MF. The company has confirmed customer incidents and has since released emergency patches to address the issue. 

The vulnerabilities include: 

  • CVE-2026-81578: An authentication bypass vulnerability that could allow an unauthenticated attacker to modify certain system configurations. 
  • CVE-2026-82078: A vulnerability that could potentially allow arbitrary code execution under specific conditions. 

Who Is Affected? 

This advisory applies to all PaperCut NG and PaperCut MF installations that have an Application Server accessible from the public internet. In simple terms, if the PaperCut web interface can be reached without being connected to your internal network or VPN, your environment may be vulnerable.  

Century Business Products has been actively monitoring this situation and has proactively contacted customers whose PaperCut servers were identified as publicly accessible. If you have not been contacted by Century regarding this advisory, your PaperCut server is not publicly facing. 

Even if it is not publicly facing, PaperCut recommends that all customers apply the latest security updates and patches. 

How to check for potential compromise 

PaperCut has identified several indicators that may warrant further investigation. 

You can check the full list of indicators of compromise here. 

PaperCut notes that the absence of these indicators does not guarantee a system has not been affected. 

Recommended Next Steps 

PaperCut’s primary recommendation is to immediately restrict access to trusted IP addresses if your server is internet-facing. Firewall rules, VPN requirements, and network access controls can help prevent access from untrusted sources. 

PaperCut also recommends installing Emergency Patch Release 2, which includes additional security hardening beyond the initial emergency release. Available patched versions include: 

  1. Version 26 → 26.0.4 
  2. Version 25 → 25.0.12 
  3. Version 24 → 24.1.9  

Customers should follow standard upgrade procedures and create backups before applying updates. PaperCut Upgrade Procedure: https://www.papercut.com/help/manuals/ng-mf/common/upgrade/ 

For customers currently running Version 25, use the v26 patch; this will also update your PaperCut version to 26 which is the most up-to-date version of PaperCut MF. 

RECAP 

Organizations using PaperCut NG or MF should: 

  1. Identify whether the PaperCut server is publicly facing. 
  2. Restrict external access where possible. 
  3. Verify backups. 
  4. Install the latest emergency patch. 
  5. Review logs and security alerts for suspicious activity. 
  6. Monitor PaperCut’s security bulletin for updates. 

While this is a developing security incident, PaperCut has provided clear mitigation guidance and updated patches to help customers protect their environments.  

Organizations that limit public exposure, apply the latest updates, and review their systems for signs of compromise will be in the best position moving forward. 

Do you have questions? Contact Century Business Products here.