Threat Intel
CISA Expands KEV Catalog with Two New PaperCut Exploits
CISA has added CVE‑2026‑81578 and CVE‑2026‑82078 to its Known Exploited Vulnerabilities list. Both target PaperCut NG/MF, allowing attackers to bypass authentication or exploit unsafe reflection to gain full control. Federal agencies must now prioritize patching under BOD 26‑04, while all organizations are urged to adopt risk‑based remediation and submit new KEV candidates.
In a swift update, the Cybersecurity and Infrastructure Security Agency (CISA) has broadened its Known Exploited Vulnerabilities (KEV) catalog to include two fresh threats that are already being leveraged in the wild.
What’s New?
- CVE‑2026‑81578 – Missing authentication in a critical function of PaperCut NG/MF, enabling attackers to execute privileged actions without valid credentials.
- CVE‑2026‑82078 – Unsafe reflection vulnerability in PaperCut NG/MF that can be abused to run arbitrary code and seize full control of the system.
Both flaws expose publicly reachable assets to total compromise, a scenario that CISA deems high‑risk and prioritizes for rapid remediation.
Why It Matters for Federal Agencies
Under Binding Operational Directive (BOD) 26‑04, Federal Civilian Executive Branch (FCEB) agencies must focus patching efforts on KEV‑listed CVEs that grant attackers full control. The directive also requires agencies to verify whether systems have been compromised before a patch is applied.
What’s Next for the Rest of the Industry?
While BOD 26‑04 applies to federal entities, CISA encourages every organization to adopt a risk‑based approach and to treat KEV entries as top‑priority fixes. The agency also invites security teams to submit evidence‑backed vulnerabilities for future KEV inclusion via its nomination form.
“CISA will continue to add vulnerabilities that meet the criteria of active exploitation and high impact,” a CISA spokesperson said. "We urge all defenders to stay ahead by patching these risks immediately."
In short: patch PaperCut NG/MF now, verify your systems, and keep an eye on the KEV catalog for any new entries that could affect your environment.