THREAT OPS › CVEs › CVE-2026-82078
CVE-2026-82078 — PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
Vulnerability details
- Affected productsNG/MF
- KEV remediation due2026-09-14
Related reporting
- [NVD] CVE-2026-82078 (CRITICAL 9.1) — An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attnvd
- Metasploit Wrap Up: This One Goes to Sixteen!rapid7
- August 2026 CVE Landscaperecordedfuture
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universitiesthehackernews
- CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilitieshorizon3
- PaperCut RCE Chain: CVE-2026-82078 Exploitedsocradar_blog
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-82078 — PaperCut NG/MF: PaperCut NG/MF Unsafe Reflection Vulnerabilitycisa_kev
- [CISA KEV] CVE-2026-81578 — PaperCut NG/MF: PaperCut NG/MF Missing Authentication for Critical Function Vulnerabilitycisa_kev
- 31th August – Threat Intelligence Reportcheckpoint_research
- PaperCut Multiple Vulnerabilitieshkcert