{"schema_version":1,"title":"PaperCut vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in PaperCut: 4 in the last 7 days and 6 in the last 90 days, 5 of them critical and 5 exploited in the wild. The most recent, CVE-2026-87739, was published on 24 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/papercut","json_url":"https://junglewise.ai/threats/vendors/papercut.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/papercut","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":1,"all_time":12,"critical":5,"exploited":5,"last_7_days":4,"last_30_days":6,"last_90_days":6,"last_365_days":10},"latest":[{"cve":"CVE-2026-87739","epss":0.0038,"slug":"cve-2026-87739-an-improper-authentication-vulnerability-in-papercut-mf-ng-allows","title":"PaperCut MF/NG authentication bypass in report generation","severity":"info","exploited":false,"published_at":"2026-09-24T07:16:34.78+00:00","url":"https://junglewise.ai/threats/cve-2026-87739-an-improper-authentication-vulnerability-in-papercut-mf-ng-allows"},{"cve":"CVE-2026-82077","epss":0.0074,"slug":"cve-2026-82077-an-improper-limitation-of-a-pathname-to-a-restricted-directory","title":"PaperCut NG/MF path traversal in Scan-to-Fax component","severity":"info","exploited":false,"published_at":"2026-09-24T07:16:33.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82077-an-improper-limitation-of-a-pathname-to-a-restricted-directory"},{"cve":"CVE-2026-11744","epss":0.0017,"slug":"cve-2026-11744-an-input-validation-vulnerability-exists-in-the-papercut-hive","title":"PaperCut Hive code injection in NFC card processing","severity":"info","exploited":false,"published_at":"2026-09-24T07:16:32.1+00:00","url":"https://junglewise.ai/threats/cve-2026-11744-an-input-validation-vulnerability-exists-in-the-papercut-hive"},{"cve":"CVE-2026-14780","epss":0.0031,"slug":"cve-2026-14780-a-vulnerability-exists-in-the-papercut-ng-mf-platform-s-device","title":"PaperCut NG/MF sandbox escape in device scripting","severity":"info","exploited":false,"published_at":"2026-09-24T06:17:00.567+00:00","url":"https://junglewise.ai/threats/cve-2026-14780-a-vulnerability-exists-in-the-papercut-ng-mf-platform-s-device"},{"cve":"CVE-2026-82078","cvss":9.1,"epss":0.0384,"slug":"cve-2026-82078-papercut-ng-mf-unsafe-reflection-vulnerability","title":"An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application in","severity":"critical","exploited":true,"published_at":"2026-08-28T16:18:31.24+00:00","url":"https://junglewise.ai/threats/cve-2026-82078-papercut-ng-mf-unsafe-reflection-vulnerability"},{"cve":"CVE-2026-81578","cvss":9.8,"epss":0.0448,"slug":"cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function","title":"An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, u","severity":"critical","exploited":true,"published_at":"2026-08-28T16:18:29.6+00:00","url":"https://junglewise.ai/threats/cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function"},{"cve":"CVE-2026-6645","cvss":7.3,"slug":"cve-2026-6645-papercut-print-deploy-insecure-process-execution-in-pc-printer","title":"PaperCut Print Deploy insecure process execution in pc-printer-updater.exe","severity":"info","exploited":false,"published_at":"2026-06-22T04:17:13.31+00:00","url":"https://junglewise.ai/threats/cve-2026-6645-papercut-print-deploy-insecure-process-execution-in-pc-printer"},{"cve":"CVE-2026-6418","cvss":4.9,"slug":"cve-2026-6418-papercut-mf-and-ng-path-traversal-in-shared-account","title":"PaperCut MF and NG path traversal in Shared Account Synchronization","severity":"medium","exploited":false,"published_at":"2026-05-05T07:16:00.97+00:00","url":"https://junglewise.ai/threats/cve-2026-6418-papercut-mf-and-ng-path-traversal-in-shared-account"},{"cve":"CVE-2026-6180","cvss":8.1,"slug":"cve-2026-6180-papercut-mf-race-condition-in-hp-badge-swipe-processing","title":"PaperCut MF race condition in HP badge-swipe processing","severity":"high","exploited":false,"published_at":"2026-05-05T07:16:00.793+00:00","url":"https://junglewise.ai/threats/cve-2026-6180-papercut-mf-race-condition-in-hp-badge-swipe-processing"},{"cve":"CVE-2023-27351","cvss":8.2,"epss":0.8696,"slug":"cve-2023-27351-papercut-ng-mf-authentication-bypass-in-securityrequestfilter","title":"PaperCut NG/MF authentication bypass in SecurityRequestFilter","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27351-papercut-ng-mf-authentication-bypass-in-securityrequestfilter"},{"cve":"CVE-2023-2533","cvss":8.8,"epss":0.3632,"slug":"cve-2023-2533-papercut-ng-mf-csrf-in-admin-interface","title":"PaperCut NG/MF CSRF in admin interface","severity":"critical","exploited":true,"published_at":"2025-07-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2533-papercut-ng-mf-csrf-in-admin-interface"},{"cve":"CVE-2023-27350","cvss":9.8,"slug":"cve-2023-27350-papercut-mf-ng-improper-access-control-vulnerability","title":"PaperCut MF/NG Improper Access Control Vulnerability","severity":"critical","exploited":true,"published_at":"2023-04-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27350-papercut-mf-ng-improper-access-control-vulnerability"}],"vendor":{"hub":true,"name":"PaperCut","slug":"papercut","homepage":"https://www.papercut.com/","description":"A software company that develops print management and control solutions.","url":"https://junglewise.ai/threats/vendors/papercut"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":2,"exploited":2,"vulnerabilities":2},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2026-81578","cvss":9.8,"epss":0.0448,"slug":"cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function","title":"An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, u","severity":"critical","exploited":true,"published_at":"2026-08-28T16:18:29.6+00:00","url":"https://junglewise.ai/threats/cve-2026-81578-papercut-ng-mf-missing-authentication-for-critical-function"},{"cve":"CVE-2023-27350","cvss":9.8,"slug":"cve-2023-27350-papercut-mf-ng-improper-access-control-vulnerability","title":"PaperCut MF/NG Improper Access Control Vulnerability","severity":"critical","exploited":true,"published_at":"2023-04-21T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27350-papercut-mf-ng-improper-access-control-vulnerability"},{"cve":"CVE-2026-82078","cvss":9.1,"epss":0.0384,"slug":"cve-2026-82078-papercut-ng-mf-unsafe-reflection-vulnerability","title":"An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application in","severity":"critical","exploited":true,"published_at":"2026-08-28T16:18:31.24+00:00","url":"https://junglewise.ai/threats/cve-2026-82078-papercut-ng-mf-unsafe-reflection-vulnerability"},{"cve":"CVE-2023-2533","cvss":8.8,"epss":0.3632,"slug":"cve-2023-2533-papercut-ng-mf-csrf-in-admin-interface","title":"PaperCut NG/MF CSRF in admin interface","severity":"critical","exploited":true,"published_at":"2025-07-28T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2533-papercut-ng-mf-csrf-in-admin-interface"},{"cve":"CVE-2023-27351","cvss":8.2,"epss":0.8696,"slug":"cve-2023-27351-papercut-ng-mf-authentication-bypass-in-securityrequestfilter","title":"PaperCut NG/MF authentication bypass in SecurityRequestFilter","severity":"critical","exploited":true,"published_at":"2026-04-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-27351-papercut-ng-mf-authentication-bypass-in-securityrequestfilter"},{"cve":"CVE-2026-6180","cvss":8.1,"slug":"cve-2026-6180-papercut-mf-race-condition-in-hp-badge-swipe-processing","title":"PaperCut MF race condition in HP badge-swipe processing","severity":"high","exploited":false,"published_at":"2026-05-05T07:16:00.793+00:00","url":"https://junglewise.ai/threats/cve-2026-6180-papercut-mf-race-condition-in-hp-badge-swipe-processing"},{"cve":"CVE-2026-6418","cvss":4.9,"slug":"cve-2026-6418-papercut-mf-and-ng-path-traversal-in-shared-account","title":"PaperCut MF and NG path traversal in Shared Account Synchronization","severity":"medium","exploited":false,"published_at":"2026-05-05T07:16:00.97+00:00","url":"https://junglewise.ai/threats/cve-2026-6418-papercut-mf-and-ng-path-traversal-in-shared-account"},{"cve":"CVE-2026-6645","cvss":7.3,"slug":"cve-2026-6645-papercut-print-deploy-insecure-process-execution-in-pc-printer","title":"PaperCut Print Deploy insecure process execution in pc-printer-updater.exe","severity":"info","exploited":false,"published_at":"2026-06-22T04:17:13.31+00:00","url":"https://junglewise.ai/threats/cve-2026-6645-papercut-print-deploy-insecure-process-execution-in-pc-printer"},{"cve":"CVE-2026-82077","epss":0.0074,"slug":"cve-2026-82077-an-improper-limitation-of-a-pathname-to-a-restricted-directory","title":"PaperCut NG/MF path traversal in Scan-to-Fax component","severity":"info","exploited":false,"published_at":"2026-09-24T07:16:33.457+00:00","url":"https://junglewise.ai/threats/cve-2026-82077-an-improper-limitation-of-a-pathname-to-a-restricted-directory"},{"cve":"CVE-2026-87739","epss":0.0038,"slug":"cve-2026-87739-an-improper-authentication-vulnerability-in-papercut-mf-ng-allows","title":"PaperCut MF/NG authentication bypass in report generation","severity":"info","exploited":false,"published_at":"2026-09-24T07:16:34.78+00:00","url":"https://junglewise.ai/threats/cve-2026-87739-an-improper-authentication-vulnerability-in-papercut-mf-ng-allows"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"PaperCut MF","slug":"mf","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/mf"},{"name":"PaperCut NG","slug":"ng","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/ng"}]}