CISA adds two PaperCut flaws to exploited vulnerabilities catalog
CISA added CVE-2026-81578 (9.8) and CVE-2026-82078 (9.1) in PaperCut NG/MF to its Known Exploited Vulnerabilities catalog on August 31, 2026, with a federal remediation deadline of September 14. Chained together, the flaws allow pre-authentication code execution, often as SYSTEM.
- CVE-2026-81578: 9.8, access control bypass in the PaperCut NG/MF web interface
- CVE-2026-82078: 9.1, unsafe class loading in database connection utilities
- Federal remediation deadline was September 14, 2026
- Campaign hit hundreds of exposed instances across dozens of countries, education among worst affected
Read next
Security