VORANT. Threat Intelligence Sign in Get the full feed

CISA adds two PaperCut flaws to KEV list

severe vulnerability government-nationaltechnology

CISA flagged two actively exploited PaperCut NG/MF vulnerabilities and ordered federal agencies to remediate under BOD 26-04.

CISA has added two vulnerabilities affecting PaperCut NG/MF print management software to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. CVE-2026-81578 is a missing authentication vulnerability for a critical function, while CVE-2026-82078 is an unsafe reflection vulnerability. Neither the article nor CISA's notice provides technical details on the exploitation chain, threat actor attribution, or specific victim organizations, but PaperCut software has historically been targeted by ransomware affiliates and other threat actors due to its widespread deployment in enterprise printing environments.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are required to prioritize remediation of KEV-listed vulnerabilities on publicly exposed assets, particularly those that could grant an attacker total control post-exploitation, and to check for prior compromise before patching. While the directive is binding only on FCEB agencies, CISA recommends all organizations using PaperCut NG/MF adopt the same risk-based prioritization and apply available patches or mitigations promptly.

Defenders should inventory any PaperCut NG/MF deployments, confirm patch status against the affected versions, and review authentication and application logs for signs of unauthorized access or exploitation attempts predating remediation, consistent with BOD 26-04's compromise-assessment requirement.

Mentioned in this report

Vulnerabilities CVE-2026-81578KEVCVE-2026-82078KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free