HIGHVulnerability
Verified
Global
CISA KEV: PaperCut NG/MF — PaperCut NG/MF Unsafe Reflection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
Analysis
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-28. Remediation due: 2026-09-11.