papercut
Safeguard articles tagged "papercut" — guides, analysis, and best practices for software supply chain and application security.
8 articles
CVE-2023-27350: PaperCut MF/NG Improper Access Control Vulnerability
CVE-2023-27350 affects PaperCut MF/NG and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-04-21.
CVE-2023-2533: PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2023-2533 affects PaperCut NG/MF and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-28.
CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability
CVE-2023-27351 affects PaperCut NG/MF and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-04-20.
CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVE-2026-81578 affects PaperCut NG/MF and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-31.
CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability
CVE-2026-82078 affects PaperCut NG/MF and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-08-31.
A Second PaperCut Authentication Bypass, This One Tied to Ransomware
CVE-2023-27351 in PaperCut's SecurityRequestFilter class bypasses authentication with no credentials at all, and CISA flags it with a confirmed ransomware association.
PaperCut Has Two More Confirmed-Exploited CVEs, After Its 2023 Ransomware History
PaperCut MF/NG, previously exploited at scale by ransomware affiliates in 2023, had two more vulnerabilities confirmed exploited on the same day in 2026 — an access control failure and unsafe class loading.
PaperCut CVE-2023-27350 Explained: Auth Bypass to Unauthenticated RCE
CVE-2023-27350 is an authentication bypass in PaperCut MF and NG that hands an attacker admin access and remote code execution, rated CVSS 9.8. Here is the timeline, root cause, and how to remediate.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.