Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Active Exploitation of PaperCut NG/MF Vulnerabilities

Source context: this article examines information published by the source on August 31, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

CISA has identified two vulnerabilities in PaperCut NG/MF that are currently being exploited in the wild. These were added to the Known Exploited Vulnerabilities (KEV) Catalog on August 31, 2026:

  • CVE-2026-81578: A “Missing Authentication for Critical Function” vulnerability.
  • CVE-2026-82078: An “Unsafe Reflection” vulnerability.

Exposure and applicability

This exposure applies to organizations utilizing PaperCut NG/MF. The risk is heightened for instances where these systems are publicly exposed; CISA notes that on such assets, exploitation may grant total control of the asset post-exploitation. While Binding Operational Directive (BOD) 26-04 specifically mandates rapid remediation for Federal Civilian Executive Branch (FCEB) agencies, CISA encourages all organizations to prioritize the remediation of these KEV Catalog vulnerabilities.

Remediation priorities

Based on the KEV designation, vulnerability management teams should prioritize these two CVEs over other pending updates that lack evidence of active exploitation. Our analysis suggests the following prioritization sequence:

  1. Asset Identification: Locate all instances of PaperCut NG/MF across the environment, prioritizing those with public-facing interfaces.
  2. Compromise Assessment: In alignment with BOD 26-04 expectations for federal agencies, defenders should investigate for signs of system compromise prior to applying updates.
  3. Rapid Remediation: Apply security updates to address both CVE-2026-81578 and CVE-2026-82078.

How to validate remediation

Verification must move beyond a simple version check or the presence of a patch. To ensure exposure is actually reduced, defenders should employ the following validation methods:

  • Functional Testing: Verify that critical functions previously lacking authentication (CVE-2026-81578) now strictly require valid credentials before execution.
  • Configuration Audit: Review system logs and configurations to ensure the “Unsafe Reflection” path (CVE-2026-82078) is no longer accessible.
  • Exposure Scanning: Use authorized scanning tools to confirm that specific vulnerability signatures are no longer detected on the network interface.

Limits and open questions

It remains unknown which specific versions of PaperCut NG/MF are affected, as the source does not list version numbers. Additionally, while remediation reduces the likelihood of future exploitation, it does not guarantee the absence of existing persistence if a system was compromised before the fix was applied. The residual risk remains for any asset that is patched without a prior compromise assessment.

Source and editorial note

CISA Adds Two Known Exploited Vulnerabilities to Catalog · Source date: August 31, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment