30 August 2026
Reference: CVE-2026-81578
1. What is being reported?
The problem is with the web management interface of PaperCut MF and NG. Attackers can send requests remotely that trigger changes in the system before the software checks if they have permission. This means someone could change settings without needing a username or password.
2. What this means in plain English
For a small organisation, this means someone outside your business could potentially interfere with your printing system. This could cause disruption, expose sensitive information, or allow further attacks if the system is connected to your network.
3. Could this affect a small business?
If your organisation uses PaperCut MF or NG software to manage printers, you could be affected. If you do not use this software, or if your IT provider manages printing differently, you are likely not affected.
4. What to do now
- Check if your organisation uses PaperCut MF or NG software for printing management.
- Contact your IT provider or software supplier immediately to confirm if you have the vulnerable versions.
- Apply any security updates or patches provided by PaperCut as soon as possible.
- Monitor your printing systems for unusual activity and report any concerns to your IT support.
5. Ask your IT provider
Can you confirm if our PaperCut MF or NG software is affected by CVE-2026-81578, and have the necessary security updates been applied to prevent unauthorised access?
6. Bottom line
If you use PaperCut printing software, act quickly to update it and protect your organisation from unauthorised changes.
Information based on CISA KEV, NVD, and reputable security reporting.