Vendor
PaperCut
As of , 5 PaperCut vulnerabilities are on CISA's list of exploited vulnerabilities, 2 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2023-27351.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2023-27351Improper Authentication | PaperCut NG/MF | Patch nowRansomware use, listed within a year | 0.78 | ||
| 2 | CVE-2026-81578Missing Authentication for Critical Function | PaperCut NG/MF | Patch this weekMetasploit module; EPSS 0.85 | 0.85 | ||
| 3 | CVE-2026-82078Unsafe Reflection | PaperCut NG/MF | Patch this weekMetasploit module; EPSS 0.61 | 0.61 | ||
| 4 | CVE-2023-27350Improper Access Control | PaperCut MF/NG | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 | ||
| 5 | CVE-2023-2533Cross-Site Request Forgery (CSRF) | PaperCut NG/MF | Patch soon | 0.29 |
Products
- NG/MF4 entries
- MF/NG1 entry
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2023 | 1 |
| 2024 | none |
| 2025 | 1 |
| 2026 | 3 |