top of page

Security Bulletin

Public·5 members

Jake Geier
Jake Geier

CISA Adds PaperCut NG/MF Vulnerabilities to KEV Catalog as Active Exploitation Confirmed


What:

  • CISA added two PaperCut NG/MF vulnerabilities — CVE-2026-81578 (missing authentication, CWE-306) and CVE-2026-82078 (unsafe reflection, CWE-470) — to its Known Exploited Vulnerabilities catalog on August 31, 2026

  • CVE-2026-81578 lets an unauthenticated attacker modify system configuration settings

  • CVE-2026-82078 allows execution of arbitrary Java bytecode already on the application classpath, under the PaperCut server process's security context

  • The two can be chained: unauthenticated config change → reflection-based code execution, enabling remote compromise of vulnerable deployments

  • CISA lists ransomware use as "unknown" for both entries — no confirmed ransomware tie yet


⚠️Impact:

  • PaperCut NG/MF is widely deployed across schools, enterprises, government agencies, and MSPs to manage printers, authentication, and quotas

  • A compromised PaperCut server is a valuable internal-network foothold given its authentication and workflow role

  • Chained exploitation is pre-auth RCE — internet-exposed management interfaces are the highest-risk exposure

  • Federal civilian agencies face a September 14, 2026 remediation deadline under BOD 22-01


💡Recommendations:

  • Apply vendor patches/mitigations per PaperCut's security bulletin without delay

  • Confirm administrative interfaces are not reachable from the public internet

  • Review PaperCut server logs, auth events, configuration-change records, and unusual Java process activity for signs of prior compromise

  • Where patching isn't immediately possible, isolate or restrict access per CISA's risk-based guidance; consider discontinuing use if mitigation isn't feasible

Read the full story HERE

2 Views
bottom of page