CISA Adds PaperCut NG/MF Vulnerabilities to KEV Catalog as Active Exploitation Confirmed

❓What:
CISA added two PaperCut NG/MF vulnerabilities — CVE-2026-81578 (missing authentication, CWE-306) and CVE-2026-82078 (unsafe reflection, CWE-470) — to its Known Exploited Vulnerabilities catalog on August 31, 2026
CVE-2026-81578 lets an unauthenticated attacker modify system configuration settings
CVE-2026-82078 allows execution of arbitrary Java bytecode already on the application classpath, under the PaperCut server process's security context
The two can be chained: unauthenticated config change → reflection-based code execution, enabling remote compromise of vulnerable deployments



