← All CVEs NewScan detects
criticalKEV

CVE-2026-81578

PaperCut MF/NG unauthenticated management-interface access control bypass chained to code execution (CISA KEV)

Severity
critical
Affected product
PaperCut MF/NG
Affected versions
PaperCut MF/NG ≥ 24.0.0, < 24.1.9
Affected versions
PaperCut MF/NG ≥ 25.0.0, < 25.0.12
Affected versions
PaperCut MF/NG ≥ 26.0.0, < 26.0.4
Fixed in
PaperCut MF/NG 24.1.9.76515 (MF) / 24.1.9.76516 (NG)
Fixed in
PaperCut MF/NG 25.0.12.76509 (MF) / 25.0.12.76510 (NG)
Fixed in
PaperCut MF/NG 26.0.4.76507 (MF) / 26.0.4.76508 (NG)
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-09-01
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.

The 24.x arm. THREE ROWS FOR ONE CVE, one per supported branch, because PaperCut ships the fix on each branch separately (MF 24.1.9.76515 / 25.0.12.76509 / 26.0.4.76507, NG one build higher in each case) - a single `lt 26.0.4` would call a fully patched 25.0.12 vulnerable. EVERY BOUND STOPS AT THE RELEASE, ONE STEP BELOW THE FIX, and the gap is deliberate: the fingerprint reads `PaperCut MF 26.0.4 (Build 76494)`, where release and build are not contiguous, so a single capture group cannot produce a build-level version to compare. An install whose release EQUALS the fixed release (24.1.9, 25.0.12, 26.0.4) therefore falls outside all three rows and degrades to the appliance advisory observation, which names this CVE and tells the operator to confirm the build - under-claiming on exactly the builds the release cannot separate, instead of a false positive on every patched install. That is the same call the CVE-2025-5777 CitrixBleed-2 row in this file made for the same reason. 23.x and earlier are absent because the advisory's coverage of them is 'possibly affected', which is not a range.

APPLIANCE FINGERPRINT

NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.

The 25.x arm of CVE-2026-81578 - read the 24.x row's note for why the branch is split and why the bound stops one release below the fix.

APPLIANCE FINGERPRINT

NewScan fingerprints the PaperCut MF/NG appliance and reports this CVE when the detected version falls inside the affected range below.

The 26.x arm of CVE-2026-81578, the branch the Metasploit module was tested against (MF 26.0.4.76494 - a build inside this branch but AT the fixed release, so the very build the module exploits is the one this row cannot gate; it lands on the advisory observation instead). Read the 24.x row's note for the reasoning.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →