Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

CISA Adds Two PaperCut Flaws to KEV Catalog

Both flaws affect PaperCut NG/MF; one is an authentication bypass, the other an unsafe reflection issue.

By TMRO Staff·2 min read

Key points

  • CISA added two vulnerabilities to KEV catalog on 2026-08-31
  • CVE-2026-81578: missing authentication for critical function
  • CVE-2026-82078: unsafe reflection vulnerability
  • Both affect PaperCut NG/MF
  • Active exploitation evidence prompted the additions

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The additions, announced on August 31, 2026, cover CVE-2026-81578, a missing authentication for critical function vulnerability, and CVE-2026-82078, an unsafe reflection vulnerability. Both affect PaperCut NG/MF, a widely used print management software.

The KEV catalog is a list of vulnerabilities that have been confirmed as exploited in the wild. CISA notes that these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. The catalog is part of the Binding Operational Directive (BOD) 26-04, which establishes vulnerability management requirements for Federal Civilian Executive Branch agencies.

Authentication bypass and unsafe reflection

CVE-2026-81578 is described as a missing authentication for critical function vulnerability. This type of flaw allows an attacker to bypass authentication mechanisms and access critical functions without proper credentials. CVE-2026-82078 is an unsafe reflection vulnerability, which can allow an attacker to execute arbitrary code or cause other unintended behavior.

Both vulnerabilities are present in PaperCut NG/MF, a product used by many organizations for print management. The exact impact and attack vectors are not detailed in the advisory, but the active exploitation evidence suggests that attackers are already leveraging these flaws.

Federal agencies under directive

The addition to the KEV catalog triggers requirements under BOD 26-04, which mandates that Federal Civilian Executive Branch agencies prioritize security updates based on risk. Agencies are expected to remediate known exploited vulnerabilities within specified timelines. While the directive applies to federal agencies, the catalog is widely used by private sector organizations as a guide for patch prioritization.

CISA's advisory does not provide specific remediation steps or timelines beyond the general requirements of BOD 26-04. Organizations using PaperCut NG/MF should monitor vendor advisories and apply patches as soon as they become available.

What happens next

The immediate next step is for affected organizations to apply available patches or mitigations. CISA's advisory does not specify when patches were released or if they are already available. The absence of patch details leaves open the question of whether fixes are currently accessible or if organizations must rely on temporary workarounds until vendors respond.

Why it matters

The KEV catalog is a key resource for prioritizing patches, especially for federal agencies under BOD 26-04. Active exploitation of these flaws means organizations using PaperCut NG/MF face immediate risk. The addition signals that attackers are actively targeting these vulnerabilities, making timely patching critical.

Sources

TMRO Report writes original coverage based on the material listed above.