CISA has added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. CVE-2026-81578 is a missing-authentication-for-critical-function flaw, while CVE-2026-82078 is an unsafe reflection vulnerability. The first is directly identity/access relevant, as it allows attackers to reach privileged functionality without proper authentication.
Under Binding Operational Directive 26-04, federal civilian agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets — especially those granting total control post-exploitation — and check whether systems were compromised before patching. PaperCut print-management servers are commonly deployed with elevated access and network reach, making them attractive footholds for lateral movement and credential harvesting.
What to take away: Organizations running PaperCut NG/MF should patch immediately and hunt for signs of prior compromise. Authentication-bypass bugs on internet-facing management servers are a classic entry point that can undermine broader identity and Active Directory security.