DIRAS TAKE
Urgent — CISA placed this vulnerability on its Known Exploited Vulnerabilities list with a remediation due date, and public exploit code exists; prioritize patching or mitigating internet-exposed PaperCut NG/MF instances immediately.
What is CVE-2026-81578?
Unauthenticated remote attackers can trigger administrative backend actions and modify system configurations in PaperCut NG/MF, tracked as CVE-2026-81578. The flaw affects 24.x before 24.1.10, 25.0.0 through before 25.0.13, and 26.0.0 through before 26.0.5. Exploitation requires network access to the product's web management interface; no valid login or user interaction is required according to the vendor's advisory.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of PaperCut NG/MF are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 24.x | before 24.1.10 | 24.1.10 |
| 25.x | 25.0.0 – before 25.0.13 | 25.0.13 |
| 26.x | 26.0.0 – before 26.0.5 | 26.0.5 |
Is CVE-2026-81578 being exploited?
CISA added CVE-2026-81578 to the Known Exploited Vulnerabilities catalog on 2026-08-31, requiring US federal agencies to address it by 2026-09-14; public exploit code is available.
How to fix CVE-2026-81578
- Upgrade PaperCut NG/MF to a fixed release: 24.1.10, 25.0.13, or 26.0.5 as appropriate for your branch.
- If you cannot patch immediately, block or restrict external network access to the product's web management interface and apply vendor-recommended mitigations.
- Monitor PaperCut logs and network telemetry for unexpected administrative actions and signs of compromise.
- Follow the vendor's guidance and CISA KEV instructions for remediation and forensic triage.
Frequently asked questions
Is CVE-2026-81578 being actively exploited?
CISA added CVE-2026-81578 to its Known Exploited Vulnerabilities catalog on 2026-08-31 (with a remediation due date of 2026-09-14), and public exploit code for the vulnerability is available.
Which PaperCut NG/MF versions are affected by CVE-2026-81578?
PaperCut NG/MF versions affected are 24.x before 24.1.10, 25.0.0 through before 25.0.13, and 26.0.0 through before 26.0.5.
Is there a patch for CVE-2026-81578?
Yes. Fixed releases are 24.1.10, 25.0.13, and 26.0.5 for the respective branches.
Does CVE-2026-81578 require authentication?
No. The issue allows unauthenticated remote requests to trigger administrative actions against the PaperCut NG/MF web management interface.
References
- nvd.nist.gov/vuln/detail/CVE-2026-81578
- cve.org/CVERecord?id=CVE-2026-81578
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578
- papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory
- All PaperCut CVEs on CVE Radar
- CVEs published in September 2026