ON August 31, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerabilities include CVE-2026-81578, a critical authentication issue in PaperCut NG/MF, and CVE-2026-82078, an unsafe reflection vulnerability also in PaperCut NG/MF.
CISA emphasizes the importance of rapid remediation of high-risk vulnerabilities as per Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize these vulnerabilities and to assess if any exploitation occurred post-patch application. While this directive applies mainly to Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management. CISA is open to additions to the KEV Catalog through a nomination process.