CVE-2026-82078: PaperCut NG/MF
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
- Vendor
- PaperCut
- Product
- NG/MF
- Vulnerability
- PaperCut NG/MF Unsafe Reflection Vulnerability
- Date added
- Aug 31, 2026
- CISA due date (U.S. federal agencies)
- Sep 14, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-470
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02