PaperCut NG/MF Missing Authentication Flaw (CVE-2026-81578) Added to CISA KEV, Chainable with CVE-2026-82078
CISA has added CVE-2026-81578, a missing-authentication-for-critical-function vulnerability in PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) catalog on 2026-08-31, indicating confirmed active exploitation in the wild. PaperCut published an urgent security bulletin on 2026-08-27 describing the flaw. No CVSS score has been published at this time.
What Happened
According to PaperCut's advisory and CISA's KEV entry, the vulnerability allows an unauthenticated remote attacker to modify certain system configurations on affected NG/MF deployments. CISA's KEV listing also notes this issue can be chained with CVE-2026-82078, though further technical detail on that follow-on vulnerability has not yet been provided in the source material available here.
Why It Matters
PaperCut NG/MF is widely deployed print-management software in enterprise, government, healthcare, and education environments — sectors that have historically been targeted following prior PaperCut authentication-bypass incidents. A missing-authentication flaw that lets an attacker alter system configuration without credentials is a serious foothold: it can be used to weaken security settings, enable further access, or serve as the first link in an exploit chain (as CISA's note about CVE-2026-82078 suggests). KEV inclusion means U.S. federal agencies are on a mandated remediation timeline, and it should be treated as a signal that broader opportunistic exploitation is likely.
What Defenders Should Do Now
- Identify all PaperCut NG/MF instances in your environment, including shadow-IT or forgotten print servers, and check them against PaperCut's advisory for affected versions and patches.
- Apply vendor patches or mitigations as soon as they are available and validated; if patching is delayed, restrict network exposure of PaperCut admin interfaces to trusted management networks only.
- Review PaperCut application and system logs for unexpected or unauthenticated configuration changes, especially around admin settings, user/authentication settings, and print provider/script configuration.
- Given the noted chaining with CVE-2026-82078, monitor for any follow-on exploitation attempts once that vulnerability's details are public — treat exposed PaperCut servers as a priority hunting target.
- Watch for anomalous outbound connections or new admin accounts/scripts on hosts running PaperCut, consistent with post-exploitation activity seen in past PaperCut incidents.
This is developing intelligence based on CISA's KEV addition and PaperCut's own bulletin; technical exploitation details and the full scope of the CVE-2026-82078 chain have not yet been fully disclosed. Defenders should monitor PaperCut's advisory directly for updates: PaperCut Security Bulletin (27 Aug 2026).