CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Summary
PaperCut NG/MF has a critical vulnerability allowing unauthenticated remote attackers to modify system configurations. This flaw can be combined with another vulnerability, CVE-2026-82078, and requires immediate mitigation according to vendor instructions and CISA guidance. Its exploitation for ransomware is currently unknown.
IFF Assessment
The vulnerability allows unauthenticated remote attackers to modify critical system configurations, posing a significant risk to system integrity and security.
Severity
The vulnerability has a high impact on integrity and availability due to the ability to modify critical system configurations remotely and without authentication. The attack complexity is low, and it can be chained with other vulnerabilities, increasing its exploitability.
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in PaperCut NG/MF poses a significant risk, allowing unauthenticated attackers to alter system settings, potentially leading to unauthorized access or further compromise. Defenders should prioritize applying vendor-provided mitigations and stay informed about CISA's guidance on prioritizing security updates, especially for internet-facing assets.