CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability

Added to the CISA Known Exploited Vulnerabilities catalog on 20 Apr 2026. Vendor: PaperCut. Product: NG/MF.

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. (due 04 May 2026)