THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities in the PaperCut NG/MF software to its Known Exploited Vulnerabilities catalog. Notably, CVE-2026-81578, with a CVSS score of 8.8, allows for pre-authentication remote code execution, and CVE-2026-82078, with a CVSS score of 9.4, enables unsafe reflection vulnerabilities. Attacks exploiting these flaws have been observed in real-world scenarios, including system reconnaissance activities without evidence of deeper compromise.
PaperCut has released emergency patches but the patching process can be complicated. Around 47% of installations still run outdated versions without fixes. CISA mandates federal agencies to address these security vulnerabilities by September 14.