ON 31 August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑81578 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects PaperCut NG/MF, a print‑management suite, and is named PaperCut NG/MF Missing Authentication for Critical Function Vulnerability. It allows an unauthenticated remote attacker to alter certain system configurations.
The vulnerability is a missing‑authentication bug that can be exploited over the network without credentials, enabling modification of critical settings. It carries a CVSS v3.1 score of 8.8, rated High. At the time of writing, PaperCut has not released a public patch, and the patch status is listed as unknown.
CISA’s inclusion in the KEV catalogue indicates that active exploitation of this flaw has been observed in the wild. No ransomware‑linked campaign has been publicly attributed to CVE‑2026‑81578. Federal agencies must apply mitigations by the remediation deadline of 14 September 2026.
CISA requires that affected Federal Civilian Executive Branch (FCEB) agencies apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Agencies should follow the applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations cannot be applied.
Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26-04 patching guidelines. All other organisations are advised to review their PaperCut NG/MF deployments for potential exposure and consider implementing network segmentation where feasible today for added security.
For full technical details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-81578 and the CISA KEV catalogue.