RaqibCTI
CVE

CVE-2026-82078

P2
PaperCut NG/MF Unsafe Reflection Vulnerability
PaperCut · NG/MF
Date added (CISA)
2026-08-31
Remediation due
2026-09-14
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16
  • Qilin ransomwarecampaignCorrelated cluster2026-09-11
  • PowerShell-based RATcampaignCorrelated cluster2026-08-31

Description

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

Source: NVD ↗ · CISA KEV Catalog ↗