highOther

CISA KEV Catalog Addition: PaperCut NG/MF Authentication Bypass and Unsafe Reflection Vulnerabilities

First seen Sep 1, 2026 · Updated Sep 1, 2026

CISAKEVPaperCutauthentication-bypassunsafe-reflectionprint-managementfederalvulnerability-managementBOD-26-04

CISA has added two actively exploited PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities catalog, one involving missing authentication for a critical function and another involving unsafe reflection. These flaws pose significant risk to organizations running PaperCut print management software, with federal agencies required to remediate under BOD 26-04.

Technical Analysis

CVE-2026-81578 is a missing authentication for critical function vulnerability in PaperCut NG/MF that could allow unauthenticated attackers to access or invoke sensitive server-side functionality. CVE-2026-82078 is an unsafe reflection vulnerability, a class of flaw historically exploited in PaperCut deployments to achieve remote code execution by manipulating Java reflection calls to instantiate arbitrary classes or invoke methods outside intended scope. PaperCut vulnerabilities of this nature have previously been chained together by ransomware affiliates and initial access brokers to gain full server control, making these additions to the KEV catalog indicative of confirmed in-the-wild exploitation. Organizations should assume that publicly exposed PaperCut instances granting total control post-exploitation are being actively targeted, consistent with BOD 26-04's risk-based prioritization criteria. If PaperCut servers are integrated into automated print workflows accessed by AI agents or agentic automation systems (e.g., document processing pipelines, RAG systems ingesting scanned documents, or agent-driven office automation), compromise of the underlying host could expose credentials, service tokens, or lateral movement paths into broader agent infrastructure.

Affected Systems

PaperCut NG and PaperCut MF, versions affected by CVE-2026-81578 and CVE-2026-82078 (specific version ranges pending vendor advisory); publicly exposed PaperCut application servers

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source material

Remediation Steps

  1. 1

    Apply Vendor Patches

    Update PaperCut NG/MF to the latest patched version addressing CVE-2026-81578 and CVE-2026-82078 as soon as vendor fixes are available.

  2. 2

    Restrict Public Exposure

    Remove PaperCut administration and application interfaces from direct internet exposure; place behind VPN or restricted network access.

  3. 3

    Compromise Assessment

    In line with BOD 26-04 guidance, check whether systems were compromised prior to patching, especially internet-facing PaperCut servers.

  4. 4

    Monitor for Exploitation Indicators

    Review logs for anomalous authentication bypass attempts, unexpected reflection-based class loading, or unusual process spawning from the PaperCut service account.

  5. 5

    Prioritize per KEV Catalog

    FCEB agencies must remediate per BOD 26-04 timelines; all organizations are encouraged to prioritize based on the KEV catalog risk criteria.

CVE / Advisory IDs

CVE-2026-81578CVE-2026-82078

Industries Most Exposed

GovernmentEducationHealthcareEnterprise/Corporate ITManaged Print Services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.