← Knowledge Center
Advisory CVE-2026-81578, CVE-2026-82078

CISA Flags Actively-Exploited PaperCut Auth Bypass in KEV Catalog

CISA has added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. CVE-2026-81578 is a missing-authentication-for-critical-function flaw, while CVE-2026-82078 is an unsafe reflection vulnerability. The first is directly identity/access relevant, as it allows attackers to reach privileged functionality without proper authentication.

Under Binding Operational Directive 26-04, federal civilian agencies must prioritize rapid remediation of KEV-listed flaws on publicly exposed assets — especially those granting total control post-exploitation — and check whether systems were compromised before patching. PaperCut print-management servers are commonly deployed with elevated access and network reach, making them attractive footholds for lateral movement and credential harvesting.

What to take away: Organizations running PaperCut NG/MF should patch immediately and hunt for signs of prior compromise. Authentication-bypass bugs on internet-facing management servers are a classic entry point that can undermine broader identity and Active Directory security.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.