CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The additions, announced on August 31, 2026, cover CVE-2026-81578, a missing authentication for critical function vulnerability, and CVE-2026-82078, an unsafe reflection vulnerability. Both affect PaperCut NG/MF, a widely used print management software.
The KEV catalog is a list of vulnerabilities that have been confirmed as exploited in the wild. CISA notes that these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. The catalog is part of the Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements for Federal Civilian Executive Branch agencies.
Authentication bypass and unsafe reflection
CVE-2026-81578 is described as a missing authentication for critical function vulnerability. This type of flaw allows an attacker to bypass authentication mechanisms and access critical functions without proper credentials. CVE-2026-82078 is an unsafe reflection vulnerability, which can allow an attacker to execute arbitrary code or cause other unintended behavior.
Both vulnerabilities are present in PaperCut NG/MF, a product used by many organizations for print management. The exact impact and attack vectors are not detailed in the advisory, but the active exploitation evidence suggests that attackers are already leveraging these flaws.
Federal agencies under directive
The addition to the KEV catalog triggers requirements under BOD 26-04, which mandates that Federal Civilian Executive Branch agencies prioritize security updates based on risk. Agencies are expected to remediate known exploited vulnerabilities within specified timelines. While the directive applies to federal agencies, the catalog is widely used by private sector organizations as a guide for patch prioritization.
CISA's advisory does not provide specific remediation steps or timelines beyond the general requirements of BOD 26-04. Organizations using PaperCut NG/MF should monitor vendor advisories and apply patches as soon as they become available.
What happens next
The immediate next step is for affected organizations to apply available patches or mitigations. CISA's advisory does not specify when patches were released or if they are already available. The absence of patch details leaves open the question of whether fixes are currently accessible or if organizations must rely on temporary workarounds until vendors respond.