PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerability
Info Listed in CISA KEV
Summary
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- PaperCut:NG/MF
Sources
- CISA KEV DATABASE
Original Links
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/?lid=2oneu2wt0ct4 reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
- https://nvd.nist.gov/vuln/detail/CVE-2026-82078 reference
Timeline
- kev_ingest CISA KEV