← back

CVE-2026-81578

KEV EPSS 1.6%
hype LIKELY HACK · 82 hack

KEV-listed, Metasploit public PoC, Rapid7 confirms in-the-wild, patch released.

What: Improper access control in PaperCut MF/NG web management interface allows unauthenticated remote attackers to modify system configurations; often chained with CVE-2026-82078 for RCE. EPSS 0.32% (very low base score).

Why it matters: KEV-listed 2026-08-31. Rapid7 published working Metasploit module and confirmed active in-the-wild exploitation. Chaining with CVE-2026-82078 enables unauthenticated RCE. PaperCut released emergency patch. Defenders actively triaging and patching.

Where it's seen: Rapid7 advisory + Metasploit PR, CISA KEV list, security blogs, trending on CVE tracking sites. Social chatter references chain exploitation confirmed, patching urgency stressed.

RISK: CRITICAL — KEV-listed, active exploitation confirmed, RCE chain, emergency patch released, broad NG/MF version impact.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/1/2026, 7:43:14 AM

Description

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

Weaknesses