PaperCut vendor intelligence
PaperCut Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting PaperCut products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 6
- Known exploited vulnerabilities affecting PaperCut products
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 1
- PaperCut KEV with sensor-observed exploitation activity
The catalog gap matters for PaperCut exposure
One of the six exploited PaperCut vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 17% of this vendor portfolio.
- 83%
- Covered by CISA
- 17%
- Beyond CISA
- 3
- Product families
Attested PaperCut vulnerabilities
6 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-39470
PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability |
NG | High | Beyond CISA | 01 Sep 2026 |
|
CVE-2026-81578
PaperCut MF/NG: Authentication Bypass |
PaperCut MF/NG | Confirmed | In CISA | 27 Aug 2026 |
|
CVE-2026-82078
PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector |
PaperCut MF/NG | Confirmed | In CISA | 30 Aug 2026 |
|
CVE-2023-27351
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication... |
NG | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-2533
PaperCut MF/NG 22.0.10 (Build 65996 2023-03-27) - Remote code execution via CSRF |
PaperCut NG/MF | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication... |
NG | Confirmed | In CISA | 21 Apr 2023 |
No PaperCut vulnerabilities match this search or filter.
Showing 6 of 6 on this page (6 PaperCut known exploited vulnerabilities).
Recurring weakness patterns
Access control, authentication, and authentication bypass by primary weakness account for three mapped occurrences across this PaperCut KEV portfolio.
CWE-284
Improper Access Control
CWE-287
Improper Authentication
CWE-305
Authentication Bypass by Primary Weakness
CWE-352
Cross-Site Request Forgery (CSRF)
CWE-470
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
CWE-749
Exposed Dangerous Method or Function