← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 28, 2026 · 10:09via Rapid7 Blog

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Brief

Overview

On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency.

At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain.

CVE ID

Description

CWE

CVSSv4

CVE-2026-81578

Read more on Rapid7 Blog