Reading a 1.2 Million PaperCut Fingerprint Count Correctly
A vulnerability chain in PaperCut NG and MF — CVE-2026-81578 (auth bypass, CVSS 9.8) and CVE-2026-82078 (class loading, CVSS 9.1) — allows remote code execution. A public PoC and a Metasploit module already exist; in September 2026 attacks were automated and large-scale.
- CVE-2026-81578 — auth bypass in PaperCut NG and MF, CVSS 9.8
- CVE-2026-82078 — dynamic class loading, CVSS 9.1
- Public PoC exists and a Metasploit module has been proposed
- ZoomEye search found 1.25M matches for app="PaperCut"
Read next
Security