CVE-2026-82078CISA KEVEPSS p99.1%

CVE-2026-82078PaperCut NG/MF Unsafe Reflection Vulnerability

PaperCut / NG/MF

Description

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

Scoring

CVSS 9.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS61.39% probability of exploitation · percentile 99.1% · 2026-10-05T12:00:23Z
Last modified2026-09-14

CISA KEV entry

Added to KEV: 2026-08-31

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.