CVE-2026-81578
Published Aug 28, 2026
Last updated 12 days ago
AI description
CVE-2026-81578 describes an improper access control vulnerability found in the web management interface of PaperCut MF and PaperCut NG. This flaw allows unauthenticated remote requests, specifically those targeting administrative functions, to initiate backend actions before the system fully completes its access validation checks. The vulnerability, categorized as CWE-306 (Missing authentication for critical function), enables an unauthenticated remote attacker to modify certain system configurations. It has been observed to be actively exploited in the wild, often in conjunction with CVE-2026-82078, to achieve broader compromise.
- Description
- An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
- Source
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- NVD status
- Analyzed
- Products
- papercut_mf, papercut_ng
CVSS 4.0
- Type
- Secondary
- Base score
- 8.8
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Exploit added on
- Aug 31, 2026
- Exploit action due
- Sep 14, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- eb41dac7-0af8-4f84-9f6d-0272772514f4
- CWE-305
- Hype score
- Not currently trending
We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @GreyNoiseIO. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: https://t.co/8AQlPZIEgr
@Shadowserver
12 Sept 2026
1761 Impressions
9 Retweets
11 Likes
3 Bookmarks
1 Reply
0 Quotes
Russian threat actors deployed hundreds of AI agents to automate exploitation of PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078. The campaign compromised 395 organizations across 48 countries while avoiding Russian and Chinese targets. Runtime segmentation could have
@aviatrixtrc
11 Sept 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Healthcare IT teams: patch PaperCut NG/MF NOW. AI agents helped compromise 440+ servers across 395 orgs in 48 countries. One school hit domain admin in 7 minutes. CVE-2026-81578 / CVE-2026-82078 https://t.co/kPaEPYPMoD
@Techsico_IT
11 Sept 2026
50 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Prasówka 11.09 1. Wydano Ubuntu 24.04.5 LTS z jądrem 7.0 HWE. 2. Setki agentów AI przejęły 440 serwerów PaperCut w 395 firmach i 48 krajach (CVE-2026-81578 i CVE-2026-82078)
@arkady86
11 Sept 2026
220 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Urgent update from PaperCut: NG/MF versions 26.0.5, 25.0.13, and 24.1.10 replace all emergency patches for two critical vulnerabilities (CVE-2026-81578 and CVE-2026-82078). Targets are actively exploiting these flaws using AI agents to breach authentication and run arbitrary http
@dailytechonx
11 Sept 2026
59 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 ⚠️数百体のAIエージェント使った攻撃でPaperCutの脆弱性が悪用され、395超の組織が侵害される:CVE-2026-81
@MachinaRecord
11 Sept 2026
139 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
A likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek) to exploit CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, compromising 395 orgs in 26 seconds at campaign scale. #DFIR_Radar https://t.co/AYSBek61A9
@DFIR_Radar
10 Sept 2026
166 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
GreyNoise says a likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek) to exploit PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078. The campaign hit 440 instances across 395 organizations in 48 countries, with first RCE in under four hours and
@XavierRiveraX
10 Sept 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 chain to unauth RCE; active data theft. Install Emergency Patch Release 3 even after earlier fixes. Treat internet-facing unpatched servers as compromised.
@snakeyesV1
8 Sept 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🖨️PaperCut NG/MF Vulnerability Chain Exploited in Active Attacks CVE-2026-81578 and CVE-2026-82078 can be chained to bypass authentication, modify system settings, and execute arbitrary Java code on PaperCut servers. 🔎Criminal IP Asset Search found: ☑️Nearly 30,000
@CriminalIP_US
7 Sept 2026
166 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🖨️ PaperCut NG/MF 취약점 공격 체인 분석 PaperCut NG/MF에서 인증 우회 + 동적 클래스 로딩 취약점을 연계해 인증되지 않은 원격 공격자가 서버에서 임의 코드를 실행할 수 있는 공격 체인이 확인됐습니다. 이번
@CriminalIP_KR
7 Sept 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#schwachstellen CVE-2026-81578: PaperCut NG/MF wird aktiv ausgenutzt – Konfiguration aus der Ferne änderbar #cisakev #cve202681578 #papercutngmf https://t.co/LyOapb9r01
@cybsecuritynews
7 Sept 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 PaperCut attacks are moving beyond RCE Attackers exploiting CVE-2026-81578 and CVE-2026-82078 are now stealing credentials, targeting SAM/LDAP secret https://t.co/S75woKBEIU #CVE #CVE202681578 #CVE202682078 #PaperCut #CredentialTheft #RCE #CyberSecurity https://t.co/dL5cG
@stem__shop
6 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut print servers (again, new wave) Chain: CVE-2026-81578 (auth bypass on the web UI) + CVE-2026-82078 (unsafe Java class load). Unauth RCE on PaperCut NG/MF. Vendor alert Aug 27. CISA KEV Aug 31. Federal due date Sep 14. Post-exploit seen: SimpleHelp RAT, Administrator17 ht
@ichbinlucasv
6 Sept 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut flaws (CVE-2026-81578/82078) exploited for credential theft in education sector US/Europe. #CyberAttack #Education #RCE
@chris_uk2026
6 Sept 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-81578 and CVE-2026-82078, both in CISA KEV, are chained to bypass auth and execute code on PaperCut print servers targeting US 🇺🇸 and European education orgs. #DFIR_Radar https://t.co/1jDxevazBo
@DFIR_Radar
5 Sept 2026
195 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 CYBER — Nouvelle vague d’attaques contre PaperCut : des serveurs NG/MF compromis servent désormais à déployer des outils d’accès distant. Les attaquants exploitent CVE-2026-81578 et CVE-2026-82078, une chaîne permettant de contourner l’authentification puis d
@ActuX_off
5 Sept 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are actively exploiting PaperCut flaws (CVE-2026-81578 & CVE-2026-82078) for credential theft targeting schools and universities. Prioritize immediate patching and monitor for unauthorized accounts. #CyberSecurity #CyberAwareness
@Lumideezy
5 Sept 2026
219 Impressions
16 Retweets
23 Likes
3 Bookmarks
8 Replies
0 Quotes
Arctic Wolf tracked unauth RCE in PaperCut via CVE-2026-81578 chained with CVE-2026-82078. The first flaw lets attackers drop files into /custom/ without creds; the second executes them directly through the web app. Hits began around 5 Sep 2026 against education targets in the US
@SecureChap
5 Sept 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 Citrix NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) is being actively exploited in the wild. PaperCut NG/MF pre-auth RCE chain (CVE-2026-81578/82078) hit CISA KEV, targeting schools & universities. Patch immediately. #infosec #CVE #0day
@ita_ipo
5 Sept 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 PaperCut Açıkları Eğitim Kurumlarını Hedef Alıyor Saldırganlar CVE-2026-81578 ve CVE-2026-82078 açıklarını zincirleyerek PaperCut sunucularında kimlik doğrulamasını aşabiliyor, kod çalıştırabiliyor ve kimlik bilgilerini çalabiliyor. https://t.co/W1i4fA
@KubbeSiber
5 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an
@OffensiveLab
5 Sept 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Today's Pack Alert: Arctic Wolf has observed attackers actively exploiting critical PaperCut flaws (CVE-2026-81578, CVE-2026-82078) to steal SAM credentials and exfiltrate data. Technical details and indicators: https://t.co/Rxs7ffvB1B #PackAlert #ThreatResearch #ArcticWolf ht
@AWNetworks
4 Sept 2026
114 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-81578 in PaperCut NG/MF - Missing authentication allows unauthenticated remote attackers to modify system configs. Listed on CISA KEV. Can chain with CVE-2026-82078. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/VFZZL0RZY0
@DFIR_Lab
4 Sept 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-82078 - PaperCut NG/MF unsafe reflection flaw allows arbitrary Java bytecode execution. CISA KEV listed. Patch by Sept 14, 2026. Can be chained with CVE-2026-81578. #CVE #PatchNow #ThreatIntel https://t.co/h1n235ZZdN
@DFIR_Lab
4 Sept 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut NG/MF: pre-auth RCE chain, exploited since Aug 26. CVE-2026-81578 (auth bypass, 8.8) + CVE-2026-82078 (unsafe class load, 9.4). Unauthenticated code on the App Server. Metasploit is public. CISA KEV Aug 31.
@HardikDagha
3 Sept 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
PaperCut zero-days (CVE-2026-82078 CVSS 9.4 + CVE-2026-81578) are being actively exploited. Three emergency patches in one week — if you stopped at patch 1 or 2, you're not done. Emergency Patch Release 3 (9/1) is cumulative. CISA KEV'd 8/31. https://t.co/DVzN6YWiGO
@OpenVPN
3 Sept 2026
246 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
PaperCut NG/MF zero-days CVE-2026-82078 (CVSS 9.4) + CVE-2026-81578 chain to unauth RCE. CISA added both to KEV Sept 1. Emergency Patch Release 2 shipped because attackers bypassed the first fix. Huntress saw it in the wild. Print servers sit deep in your net. #ZeroDay #InfoSec
@infrasecserv
3 Sept 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 [ACTIVE EXPLOITATION] — PAPERCUT SAYS A SECOND WAVE OF ATTACKS IS NOW HITTING UNPATCHED INTERNET-FACING SERVERS WITH MORE SOPHISTICATED POST-COMPROMISE ACTIVITY Attackers are exploiting: CVE-2026-81578 + CVE-2026-82078 and researchers have observed actors: DUMPING DATA
@XQOPTRX
3 Sept 2026
81 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CYBER — Deux failles critiques de PaperCut NG/MF sont activement exploitées. CVE-2026-81578 + CVE-2026-82078 peuvent être chaînées pour contourner l’authentification et exécuter du code à distance sur un serveur PaperCut. Les attaques ont évolué vers de vérita
@ActuX_off
3 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 are actively exploited zero-days in PaperCut NG/MF, chaining an auth bypass to unsafe Java class loading for pre-auth RCE as SYSTEM. Both are in CISA KEV; federal remediation deadline is September 14, 2026. - CVE-2026-81578 lets an ht
@DFIR_Radar
2 Sept 2026
177 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2026-81578: PaperCut NG/MF Pre-Auth RCE Added to CISA KEV — Detection and R… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-81578…" 🔗 https://t.co/oqEM5puUWw #CyberSecurity #ThreatIntel #cve #zeroday #patc
@SecurityAr58409
2 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV, Aug 31: two PaperCut NG/MF bugs. CVE-2026-81578 (no auth needed) chains with CVE-2026-82078 (unsafe reflection) for RCE. Federal remediation deadline Sep 14. Check if your print server is internet-facing.
@Frankly_Alen
2 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DEEP DIVE — CVE-2026-81578: unauthenticated config-write in PaperCut NG/MF, chained to CVE-2026-82078 for SYSTEM-level RCE. KEV-listed, exploited in the wild. If it reports 25.0.12 you can still be on the bypassable build. Check the build number. https://t.co/0nO5wvgh4d
@DailyCVEBrief
2 Sept 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
PaperCut NG/MF zero-days CVE-2026-82078 (CVSS 9.4) + CVE-2026-81578 chain to unauth RCE. CISA added both to KEV Sept 1. Emergency Patch Release 2 shipped because attackers bypassed the first fix. Huntress saw it in the wild. Print servers sit deep in your net. #ZeroDay #InfoSec
@infrasecserv
2 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-82078 (CVSS 9.4) chained with CVE-2026-81578 (CVSS 8.8) gives pre-auth RCE on PaperCut NG/MF; first patch was bypassed, requiring Emergency Patch Release 2. #DFIR_Radar https://t.co/09Ikj4rwUH
@DFIR_Radar
2 Sept 2026
183 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
PaperCut NG ve MF için sıfır-gün zafiyet zinciri: CVE-2026-81578 ve CVE-2026-82078 aktif istismarda, CISA KEV emri https://t.co/xZ34YsJrOf #CISAKEV #CVE202681578 #CVE202682078
@EnvanterMedya
2 Sept 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Print servers are not “low risk”, PaperCut just proved it. CVE-2026-81578 + CVE-2026-82078 (PaperCut NG/MF): unauth config change chained to unsafe reflection → RCE. Now on CISA’s KEV list. Due date 14 Sep. Attacks already moved from recon to hands-on-keyboard + RATs.
@PadhiyarRushi
2 Sept 2026
130 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to compromise PaperCut print servers and dump database tables for data theft. TRC analysis shows threat actors pivoted from compromised servers to access internal database systems across the network. Runtime segmentation
@aviatrixtrc
2 Sept 2026
83 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCutのゼロデイ 脆弱性、CISAがCVE-2026-81578/82078をKEV追加 Huntressが認証前RCEを再現 https://t.co/8HBQUqbdiS #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
@securityLab_jp
2 Sept 2026
82 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security Bulletin: PaperCut NG/MF vulnerabilities CVE-2026-82078 (9.4) and CVE-2026-81578 (8.8) are actively exploited. Install Emergency Patch Release 2 immediately, even if the original patch was applied. #ThreatIntel #RedLeggCTI https://t.co/A5QL4NTqLk
@RedLegg
1 Sept 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: https://t.co/ysTAPux1X6
@Shadowserver
1 Sept 2026
1640 Impressions
5 Retweets
5 Likes
1 Bookmark
1 Reply
1 Quote
PaperCut NG/MF: attackers chained CVE-2026-81578 + CVE-2026-82078. No login. Defused saw Derby DB dumps. CISA added both to KEV Aug 31. #cybersecurity #infosec #CISA #KEV #PaperCut
@Caldura7
1 Sept 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut Zero-Days Exploited in Active Data Theft Attacks Attackers are abusing PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078 to bypass authentication and dump embedded… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #papercut http
@HotaSamit
1 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added PaperCut CVE-2026-82078 and CVE-2026-81578 to KEV after active intrusions. Patch now and assume exposed, unpatched systems are compromised. Apex Cyber Guardians can help. #CyberSecurity https://t.co/geC10FZev0
@apcyberguard
1 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut CVE-2026-82078 and CVE-2026-81578 are now on CISA's KEV list and being used in active data theft campaigns. Print management servers sitting inside your AVD or VDI network segment with no micro-segmentation are a lateral movement risk here, not just a print risk. Patch
@markovichio
1 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Patch Now | September 1, 2026 Bringing these critical vulnerabilities to your attention: 🔴 Citrix NetScaler ADC/Gateway(CVE-2026-8452, CVSS 8.8) 🟠 Microsoft Windows AFD.sys (CVE-2026-68820, CVSS 7.0) 🔴 PaperCut NG/MF (CVE-2026-81578 & CVE-2026-82078, CVSS 8.
@CERT_UG
1 Sept 2026
115 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
Η CISA επιβεβαίωσε ενεργή εκμετάλλευση δύο ευπαθειών στο PaperCut (CVE-2026-82078, CVE-2026-81578). Επιχειρήσεις και δημόσιοι φορείς που το χρησιμοποιούν πρέπει να προχωρήσ
@imetrixgr
1 Sept 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PaperCut NG/MF zero-days (CVE-2026-82078, CVE-2026-81578) are now in CISA KEV and driving data theft, while JFrog Artifactory auth bypass CVE-2026-82329 is under active exploitation days after disclosure. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1RTfujYNTK
@itsalreadywhen
1 Sept 2026
69 Impressions
0 Retweets
1 Like
0 Bookmarks
2 Replies
0 Quotes
On Aug. 31, 2026, CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog; Sept. 1 reports tied scanning to real intrusions. Chained, the PaperCut flaws allow unauthenticated configuration changes and server-context code execution.
@Securehup
1 Sept 2026
53 Impressions
0 Retweets
3 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F2AF3AB4-FD10-4DE1-B906-011F45948BD0",
"versionEndExcluding": "24.1.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8F6ED0B8-62DC-4CF9-9810-2CCB824FBCA8",
"versionEndExcluding": "25.0.12",
"versionStartIncluding": "25.0.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*",
"matchCriteriaId": "51E91B81-E311-4BB9-A753-671F0C59E7F7",
"versionEndExcluding": "26.0.4",
"versionStartIncluding": "26.0.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"matchCriteriaId": "44FCDCDE-4126-4F4F-89FC-D44924F45C82",
"versionEndExcluding": "24.1.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9E727ABD-0007-424D-AB07-FB7816E43792",
"versionEndExcluding": "25.0.12",
"versionStartIncluding": "25.0.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:papercut:papercut_ng:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3938B71A-CB14-4017-A037-7D5F08DAFB13",
"versionEndExcluding": "26.0.4",
"versionStartIncluding": "26.0.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]