CISA adds critical PaperCut vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF, to its Known Exploited Vulnerabilities catalog. The flaws allow for authentication bypass and unsafe reflection, enabling unauthenticated remote code execution. Security researchers confirmed "point and shoot" exploitation in the wild, leading to full server compromise. Federal agencies are mandated to remediate the vulnerabilities by mid-September to mitigate significant risks to the federal enterprise.
Date: August 31, 2026
Location: District of Columbia, United States
Conflict: Other
Category: cyber
Severity: HIGH
Source: CISA