On 31 August CISA added CVE-2026-82078 and CVE-2026-81578 in PaperCut NG and MF to the KEV catalogue. The two chain into code execution. The vendor said on 27 August that it was investigating active exploitation, and advises closing the web interface to the internet immediately.
- CVE-2026-81578 (CVSS 8.8): under specific conditions a request without a password can change certain server settings.
- CVE-2026-82078 (CVSS 9.4): through those settings an attacker reaches Java code execution with the privileges of the PaperCut process.
- Emergency patches have been shipping since 28 August; the first step is web interface access from trusted addresses only.
The print server. Nobody counts it as the perimeter, until it turns out to be on it.
PaperCut counts who prints what, and its website lists schools, universities and hospitals among its customers. Now that very server is a target.
The chain is textbook, and that is exactly why it is dangerous. The first flaw can let a stranger change settings without a password. The second turns settings into code execution. Separately they are unpleasant. Together they are an open door.
What you do today
PaperCut states the first step without hedging: if your server is reachable from the internet, restrict web interface access to trusted addresses only, immediately, even if you have seen nothing suspicious. Then the patch, then the logs.
In server.log you look for lines with No suitable driver found for jdbc:no:x and card-number lookup errors starting with VALUES CAST. Those are the traces the vendor itself gives. Their absence does not mean you are clean, and the vendor says that too.
The printer is the last place you look for a breach, which is why it is the first thing you check this week.