CVE-2019-12135: PaperCut MF

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19.0.3 and earlier allows remote attackers to execute arbitrary code via an unspecified vector.

Affected products

  • PaperCut PaperCut MF: up to and including 18.3.8; from 19.0.1, up to and including 19.0.3
  • PaperCut PaperCut NG: up to and including 18.3.8; from 19.0.1, up to and including 19.0.3

Published 2019-06-06. Last modified 2026-06-17.