Vendor

PaperCut

As of , 5 PaperCut vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2023-27351.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-27351Improper AuthenticationPaperCut NG/MFPatch nowRansomware use, listed within a year0.78
2CVE-2026-81578Missing Authentication for Critical FunctionPaperCut NG/MFPatch this weekMetasploit module; EPSS 0.850.85
3CVE-2026-82078Unsafe ReflectionPaperCut NG/MFPatch this weekMetasploit module; EPSS 0.610.61
4CVE-2023-27350Improper Access ControlPaperCut MF/NGPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
5CVE-2023-2533Cross-Site Request Forgery (CSRF)PaperCut NG/MFPatch soon0.29

Products

  • NG/MF4 entries
  • MF/NG1 entry

Added each year

1232023: 1120232024: nonenone20242025: 1120252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20231
2024none
20251
20263

Used in ransomware

Changes CISA made to these entries

  1. CVE-2023-27351 PaperCut NG/MFRansomware use: Unknown to Known.

Every change we recorded