← Blog · · df00tech

CISA Adds PaperCut NG/MF Unsafe Reflection Flaw to KEV — Chainable with Prior CVE for RCE

breaking kev PaperCut CVE-2026-82078

What Happened

CISA has added CVE-2026-82078, an unsafe reflection vulnerability in PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild. Per PaperCut's security bulletin, the flaw allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode already present on the application classpath, running under the security context of the PaperCut server process. PaperCut notes this vulnerability can be chained with CVE-2026-81578 to increase impact. No CVSS score has been published at this time, and PaperCut's advisory is the authoritative source for affected version ranges.

Why It Matters

PaperCut NG/MF is widely deployed print management software in enterprise and public-sector environments, and the product has a history of being targeted by ransomware affiliates in prior incidents. A KEV listing means CISA has evidence of real-world exploitation, not just theoretical risk — federal agencies are required to remediate on an accelerated timeline, and any organization running PaperCut NG/MF should treat this with equivalent urgency. Because exploitation runs code under the server process's own security context and can be chained with a second vulnerability (CVE-2026-81578), successful attacks may extend beyond initial access into deeper compromise of the host.

What Defenders Should Do Now

  • Identify all PaperCut NG/MF instances in your environment and check them against PaperCut's bulletin for affected versions and available patches.
  • Prioritize patching or applying vendor-recommended mitigations, especially on internet-facing or otherwise exposed PaperCut servers.
  • Review PaperCut server process logs and configuration change history for unexpected modifications to system configuration parameters, which is the mechanism described in this flaw.
  • Watch for anomalous child processes, unexpected class-loading behavior, or outbound connections originating from the PaperCut application service account.
  • Given the note about chaining with CVE-2026-81578, ensure that vulnerability is also tracked and remediated — patching only one may leave an exploitable path.
  • Cross-reference exposed PaperCut instances against CISA KEV and internal vulnerability management SLAs.

Developing Intel

This is a same-day KEV addition and details are still emerging; exploit chains, affected version scope, and TTPs may be refined as PaperCut and researchers publish further information. Consult PaperCut's official security bulletin for authoritative guidance: PaperCut Security Bulletin (27 Aug 2026).

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.