PaperCut known exploited vulnerabilities
CISA lists 5 PaperCut CVEs as exploited in the wild. 3 were added in the last 12 months (latest 2026-08-31), and 2 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2023-27350 (MF/NG): EPSS 100.0%, added 2023-04-21
- CVE-2023-27351 (NG/MF): EPSS 78.1%, added 2026-04-20
- CVE-2023-2533 (NG/MF): EPSS 29.2%, added 2025-07-28
- CVE-2026-81578 (NG/MF): EPSS 4.5%, added 2026-08-31
- CVE-2026-82078 (NG/MF): EPSS 3.8%, added 2026-08-31
Most affected PaperCut products
NG/MF (4), MF/NG (1).
All PaperCut CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-82078 | NG/MF | NG/MF Unsafe Reflection | 2026-08-31 | 2026-09-14 | 3.8% | – |
| CVE-2026-81578 | NG/MF | NG/MF Missing Authentication for Critical Function | 2026-08-31 | 2026-09-14 | 4.5% | – |
| CVE-2023-27351 | NG/MF | NG/MF Improper Authentication | 2026-04-20 | 2026-05-04 | 78.1% | Yes |
| CVE-2023-2533 | NG/MF | NG/MF Cross-Site Request Forgery (CSRF) | 2025-07-28 | 2025-08-18 | 29.2% | – |
| CVE-2023-27350 | MF/NG | MF/NG Improper Access Control | 2023-04-21 | 2023-05-12 | 100.0% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors