Defensive self-check · CISA KEV 2026-08-31
PaperCut NG and MF CVE-2026-82078 and CVE-2026-81578: version self-check
CISA added both issues to the Known Exploited Vulnerabilities catalog on 2026-08-31. PaperCut published the fix on 2026-08-27 and says it applies to every NG and MF version. This page tells you which release to compare and which records to review on a server you own. It does not describe how to exploit either issue.
Fixed versions
- 26 is fixed in 26.0.5.
- 25 is fixed in 25.0.13.
- 24 is fixed in 24.1.10.
- PaperCut says the advisory applies to all NG and MF versions, including servers that are not on the public internet.
Check these three things
- Version. In the PaperCut admin interface open About and read the version. It should be 26.0.5, 25.0.13, 24.1.10, or a newer release on that line.
- Admin accounts. Compare the administrator list with the people who should have access. Look for accounts added after 2026-08-27.
- Settings. Review print-server and database settings changed after 2026-08-27 that were not part of an upgrade you ran.
What to do
Upgrade from the PaperCut admin interface or the vendor download before you keep investigating. If the server was behind the fix, keep it on the patched release and review the account and settings lists above.
Vendor records: the PaperCut security bulletin of 27 August 2026 and the CISA KEV catalog, entries CVE-2026-82078 and CVE-2026-81578.