• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-81578: pre-auth configuration modification in PaperCut NG/MF

Unauthenticated remote attackers can trigger administrative backend actions and modify system configurations in PaperCut NG/MF, tracked as CVE-2026-81578. The flaw affects 24.x before 24.1.10, 25.0.0 through before 25.0.13, and 26.0.0 through before 26.0.5. Exploitation requires network access to the product's web management interface; no valid login or user interaction is required according to the vendor's advisory.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.04481
CWE
CWE-305
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA placed this vulnerability on its Known Exploited Vulnerabilities list with a remediation due date, and public exploit code exists; prioritize patching or mitigating internet-exposed PaperCut NG/MF instances immediately.

What is CVE-2026-81578?

Unauthenticated remote attackers can trigger administrative backend actions and modify system configurations in PaperCut NG/MF, tracked as CVE-2026-81578. The flaw affects 24.x before 24.1.10, 25.0.0 through before 25.0.13, and 26.0.0 through before 26.0.5. Exploitation requires network access to the product's web management interface; no valid login or user interaction is required according to the vendor's advisory.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of PaperCut NG/MF are affected?

BRANCHAFFECTEDFIXED
24.xbefore 24.1.1024.1.10
25.x25.0.0 – before 25.0.1325.0.13
26.x26.0.0 – before 26.0.526.0.5

Is CVE-2026-81578 being exploited?

CISA added CVE-2026-81578 to the Known Exploited Vulnerabilities catalog on 2026-08-31, requiring US federal agencies to address it by 2026-09-14; public exploit code is available.

How to fix CVE-2026-81578

  1. Upgrade PaperCut NG/MF to a fixed release: 24.1.10, 25.0.13, or 26.0.5 as appropriate for your branch.
  2. If you cannot patch immediately, block or restrict external network access to the product's web management interface and apply vendor-recommended mitigations.
  3. Monitor PaperCut logs and network telemetry for unexpected administrative actions and signs of compromise.
  4. Follow the vendor's guidance and CISA KEV instructions for remediation and forensic triage.

Frequently asked questions

Is CVE-2026-81578 being actively exploited?

CISA added CVE-2026-81578 to its Known Exploited Vulnerabilities catalog on 2026-08-31 (with a remediation due date of 2026-09-14), and public exploit code for the vulnerability is available.

Which PaperCut NG/MF versions are affected by CVE-2026-81578?

PaperCut NG/MF versions affected are 24.x before 24.1.10, 25.0.0 through before 25.0.13, and 26.0.0 through before 26.0.5.

Is there a patch for CVE-2026-81578?

Yes. Fixed releases are 24.1.10, 25.0.13, and 26.0.5 for the respective branches.

Does CVE-2026-81578 require authentication?

No. The issue allows unauthenticated remote requests to trigger administrative actions against the PaperCut NG/MF web management interface.

References