Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
9.8 critical · over the network, without login · CISA deadline was 12 May 23
7.5 high · over the network, without login · CISA deadline was 4 May
- CVE-2026-81578PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
9.8 critical · over the network, without login · CISA deadline was 14 Sept
- CVE-2026-82078PaperCut NG/MF Unsafe Reflection Vulnerability
9.1 critical · over the network, with admin rights only · CISA deadline was 14 Sept
- CVE-2023-2533PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
8.8 high · over the network, without login, needs user action · CISA deadline was 18 Aug 25
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
Version history & changelog · as detected by patchletter
No releases recorded yet — the source was just added.
An email as soon as a new PaperCut NG/MF version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current PaperCut NG/MF version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/papercut)https://patchletter.com/badge/papercut.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).