CISA Adds PaperCut NG/MF Vulnerabilities to KEV Catalog as Active Exploitation Confirmed

❓What:
CISA added two PaperCut NG/MF vulnerabilities — CVE-2026-81578 (missing authentication, CWE-306) and CVE-2026-82078 (unsafe reflection, CWE-470) — to its Known Exploited Vulnerabilities catalog on August 31, 2026
CVE-2026-81578 lets an unauthenticated attacker modify system configuration settings
CVE-2026-82078 allows execution of arbitrary Java bytecode already on the application classpath, under the PaperCut server process's security context
The two can be chained: unauthenticated config change → reflection-based code execution, enabling remote compromise of vulnerable deployments
CISA lists ransomware use as "unknown" for both entries — no confirmed ransomware tie yet
⚠️Impact:
PaperCut NG/MF is widely deployed across schools, enterprises, government agencies, and MSPs to manage printers, authentication, and quotas
A compromised PaperCut server is a valuable internal-network foothold given its authentication and workflow role
Chained exploitation is pre-auth RCE — internet-exposed management interfaces are the highest-risk exposure
Federal civilian agencies face a September 14, 2026 remediation deadline under BOD 22-01
💡Recommendations:
Apply vendor patches/mitigations per PaperCut's security bulletin without delay
Confirm administrative interfaces are not reachable from the public internet
Review PaperCut server logs, auth events, configuration-change records, and unusual Java process activity for signs of prior compromise
Where patching isn't immediately possible, isolate or restrict access per CISA's risk-based guidance; consider discontinuing use if mitigation isn't feasible
Read the full story HERE
