ZeroDayAlert

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

PaperCut NG/MF Added to KEV 2026-08-31 Federal due 2026-09-14 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

PaperCut NG/MF deployments are vulnerable to unsafe reflection that allows attackers to execute arbitrary Java bytecode under the server process identity. The vulnerability permits manipulation of system configuration parameters. The record does not specify which versions of NG/MF are affected or whether on-premises and cloud deployments are equally exposed.

How to check whether this touches you

  • Search your asset register for PaperCut NG or MF instances; note their deployment type (on-premises, cloud-hosted, or hybrid).
  • Confirm network reachability to each instance from the internet or from untrusted internal segments; check firewall rules and access controls.
  • Retrieve the running version from the PaperCut admin interface or system logs; version alone is not definitive proof of exposure because vendors sometimes backport fixes, so cross-reference the build number against PaperCut's security advisories.
  • If you use a cloud-hosted PaperCut service, verify with your provider whether they have applied mitigations.

What to do

  1. Stop or restrict network access to PaperCut NG/MF instances until you have confirmed the running version and availability of patches; apply firewall rules to limit inbound connectivity to authorised users only.
  2. Check PaperCut's official security bulletin and the vendor's remediation guidance for your specific version; apply patches or mitigations in line with CISA BOD 26-04 timelines.
  3. If patches are unavailable and mitigations do not adequately reduce risk for your use case, escalate to stakeholders for a decision on discontinuing the product or accepting compensating controls.
  4. Enable detailed logging on the PaperCut server and on network access points; log at least authentication attempts, configuration changes, and Java bytecode execution or reflection events.
  5. If you operate a cloud instance of PaperCut, request written confirmation from the vendor that mitigations have been applied to your tenant.

If you find you were exposed

Exploitation of unsafe reflection typically precedes public disclosure by weeks or months. Begin log analysis from at least 90 days before the CVE addition date (31 August 2026), looking for anomalous configuration changes, unusual Java exception traces, or process spawning under the PaperCut server user. Log retention is the limiting factor; if your audit trail extends only 30 days, you will miss most historical activity and must rely on endpoint detection tools or file integrity monitoring to spot signs of compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-82078 is being exploited. It cannot tell you whether NG/MF is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →