<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1741336722824154&amp;ev=PageView&amp;noscript=1">
Skip to the main content.
Print Solutions

Benefit from smart ideas, lower costs, greater productivity. Choose from award-winning printers, software solutions and consumables

Insights

We combine professional expertise with a human kind of partnership

Support Centre

Get the right help and advice, register a product and see why our commitment to you matters.

Kyocera_lead_Huon_IT_co branding_RGB

Critical Security Advisory – PaperCut NG/MF Actively Exploited Vulnerabilities (CVE-2026-82078 & CVE-2026-81578)

Critical Security Advisory – PaperCut NG/MF Actively Exploited Vulnerabilities (CVE-2026-82078 & CVE-2026-81578)

We'd like to make you aware of two security vulnerabilities affecting PaperCut NG and PaperCut MF print management software. These are being actively exploited in the wild, with PaperCut confirming real customer incidents, so we recommend treating this as an emergency rather than routine patching. When chained together, the two flaws allow a remote, unauthenticated attacker to run code on the PaperCut Application Server.

Summary of the Vulnerabilities:
  • CVE-2026-82078 (CVSS 9.4, Critical) – Unsafe dynamic class loading in the database connector, allowing arbitrary code execution on the server.

     

  • CVE-2026-817578 (CVSS 8.8, High) – An access-control flaw in the web management interface that lets an unauthenticated attacker edit server configuration.

     

  • Chained together, these result in unauthenticated remote code execution (RCE).

     

  •  Full PaperCut advisory can be found here.
 
What's Affected:
  • All versions of PaperCut NG and PaperCut MF prior to the emergency patch are considered affected, your version number alone does not tell you whether you're exposed.
  • The greatest immediate risk is to Application Servers reachable from the public internet. Internal-only installations carry lower immediate risk but should still be patched.

Recommended Action:
  1. Restrict access now. If your PaperCut Application Server is reachable from the public internet, immediately restrict its web interface to trusted (internal) IP addresses using firewall rules or network access controls. PaperCut advises doing this even if you've seen no suspicious activity — it's the single most effective step while patching is arranged.

  2. Apply Emergency Patch (Release 2). PaperCut has released Emergency Patch Release 2 covering versions 24, 25, and 26 across Windows, Linux, and macOS. This supersedes the original emergency patch and includes additional hardening, we recommend installing it even if you've already applied the first patch.

Because the vulnerabilities are already being exploited and the technical details are public, unpatched servers are at real and ongoing risk. Prompt action matters here.

At Kyocera, we understand the critical importance of securing your infrastructure. If you need assistance in reviewing or resolving this issue, please don't hesitate to contact our team. You can reach our helpdesk at help@dau.kyocera.com