
What CISA Added
CISA added two actively exploited PaperCut flaws to the Known Exploited Vulnerabilities catalog: CVE-2026-81578, a missing-authentication vulnerability for a critical function, and CVE-2026-82078, an unsafe-reflection issue in PaperCut NG and PaperCut MF.
That is the point where this stops being one more vendor-security update. KEV additions mean CISA has evidence of real exploitation activity, which should move affected systems into the front row of the remediation queue.
Why PaperCut Deserves More Respect Than It Usually Gets
PaperCut is exactly the kind of infrastructure that gets underestimated. It often sits between workplace technology, server administration, identity, and branch-office operations, which means ownership can be fuzzy and monitoring can be shallow.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
That combination is what makes exploited flaws here dangerous. A product that feels peripheral to core security operations can still touch authentication paths, print release workflows, directory integration, and internal server access in ways that create a long cleanup tail if teams move slowly.
What The KEV Label Changes Operationally
The useful shift is timing. Once a flaw is on the KEV list, defenders lose the luxury of treating patching as routine maintenance. The first job becomes exposure mapping: finding every PaperCut deployment, determining which versions and configurations are in play, and deciding whether any instances are exposed more broadly than expected.
CISA's BOD 26-04 framing also matters because it reflects a simple reality: when a product can grant high privilege or meaningful network reach after exploitation, lagging asset visibility becomes just as dangerous as lagging patch velocity.
What Teams Should Do Next
Treat this as same-day ownership and exposure work, not only a patch announcement.
- Inventory every PaperCut NG and MF deployment, including inherited branch systems, secondary offices, and any instance managed outside the main server team.
- Map the listed CVEs to real versions and real hosts immediately, then identify any system exposed to untrusted networks, vendor access, or shared admin paths.
- Move remediation for affected PaperCut infrastructure ahead of routine backlog work and document who owns each environment before the response stalls on accountability.
- Review admin access, recent configuration changes, authentication activity, and adjacent server telemetry for signs the issue may already have moved beyond vulnerability exposure.
- Brief stakeholders early if print-management systems touch regulated workflows, sensitive departments, or business operations that would be painful to recover under time pressure.
Source Context
CyberExperts used CISA's KEV alert as the primary source for this article and preserved the details defenders need first: the two PaperCut CVEs, the fact that active exploitation exists, and the operational implication that vulnerable print infrastructure must now be treated as a front-of-queue exposure problem.
Related In The Daily Brief
See this item in The 5-Minute Cyber Brief