logo

Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities

ID: d67852ba-ad83-5a45-afb4-7c43b2d5a4a5

STIX ID: report--d67852ba-ad83-5a45-afb4-7c43b2d5a4a5

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Divya

...
...

Rapid7’s Metasploit Framework is adding an exploit module targeting two actively exploited PaperCut MF/NG vulnerabilities (CVE-2026-81578 and CVE-2026-82078) that enable remote code execution; the module has been submitted as PR #21842 and supports multiple PaperCut branches. The chain was reported as a zero-day in the wild and PaperCut confirmed incidents; the Metasploit module reportedly bypasses the vendor's first emergency patch but is mitigated by the vendor's second emergency patch; administrators are urged to apply Release 2, restrict web access, and hunt for listed signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.