Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw Found in PaperCut Printing Software

A serious security weakness has been found in PaperCut MF and NG, popular print management software. This flaw could let attackers run harmful code on your system if they can change certain settings. Because PaperCut is often used in offices, this is important for small businesses to address quickly.

29 August 2026

Reference: CVE-2026-82078

1. What is being reported?

The problem lies in how PaperCut loads database drivers. It does not properly check which drivers are allowed, so if someone can change configuration settings, they might make the software run dangerous code. This could let attackers take control of the system running PaperCut.

2. What this means in plain English

If an attacker exploits this flaw, they could potentially access sensitive information, disrupt printing services, or use your system to attack others. This risk is serious because it can happen remotely and without your knowledge.

3. Could this affect a small business?

Small businesses using PaperCut MF or NG for managing printers could be affected, especially if the software is connected to the internet or if untrusted people have access to system settings. Organisations not using PaperCut or those with strict access controls are less likely to be impacted.

4. What to do now

  • Check if your organisation uses PaperCut MF or NG software.
  • Contact your software supplier or IT provider to confirm if you have the vulnerable versions.
  • Apply any available security updates or patches from PaperCut immediately.
  • Restrict access to PaperCut configuration settings to trusted personnel only.

5. Ask your IT provider

Can you confirm if our PaperCut MF or NG software is affected by CVE-2026-82078, and have the necessary security updates been applied to prevent remote code execution?

6. Bottom line

If you use PaperCut printing software, act quickly to update and secure it to prevent attackers from taking control.

Information based on NVD, CISA KEV, and reputable security reporting.

Back to Vulnerability Briefs