{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/papercut-ng/mf-26.x--26.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-11744"},{"id":"CVE-2026-14780"},{"id":"CVE-2026-82077"},{"id":"CVE-2026-87739"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PaperCut Hive Embedded Application (\u003c 2.3.0)","PaperCut NG/MF 25.x (\u003c 25.0.13)","PaperCut NG/MF 26.x (\u003c 26.0.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","patch-management"],"_cs_type":"advisory","_cs_vendors":["PaperCut"],"content_html":"\u003cp\u003eThe French National Cybersecurity Agency (ANSSI) has issued an advisory regarding multiple vulnerabilities identified in various PaperCut software products. These security flaws impact PaperCut Hive Embedded Application, PaperCut NG/MF 25.x, and PaperCut NG/MF 26.x. The identified vulnerabilities pose significant risks, including potential remote code execution (RCE), unauthorized data disclosure, and remote cross-site scripting (XSS) attacks. Attackers who exploit these vulnerabilities could potentially bypass established security policies or gain unauthorized access to sensitive data processed by print management systems. Organizations utilizing affected versions are advised to update their deployments immediately to the versions specified by the vendor as secured.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in a complete compromise of the print management server or application, leading to data confidentiality breaches, unauthorized execution of arbitrary code, and the potential for cross-site scripting attacks against administrative interfaces. These systems are typically deployed across corporate and institutional networks, making them high-value targets for internal reconnaissance and lateral movement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the patching of all affected PaperCut instances to the secure versions listed in the vendor security bulletin.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade PaperCut Hive Embedded Application to version 2.3.0 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade PaperCut NG/MF 25.x to version 25.0.13 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade PaperCut NG/MF 26.x to version 26.0.5 or later.\u003c/li\u003e\n\u003cli\u003eReview the official PaperCut security bulletin (linked in references) for full technical details regarding CVE-2026-11744, CVE-2026-14780, CVE-2026-82077, and CVE-2026-87739.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T13:57:16Z","date_published":"2026-09-24T13:57:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-papercut-vulnerabilities/","summary":"PaperCut has released security updates addressing critical vulnerabilities including remote code execution, unauthorized data access, and XSS across PaperCut Hive and PaperCut NG/MF platforms.","title":"Multiple Vulnerabilities in PaperCut Software","url":"https://feed.craftedsignal.io/briefs/2026-09-papercut-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - PaperCut NG/MF 26.x (\u003c 26.0.5)","version":"https://jsonfeed.org/version/1.1"}