CISA flags two PaperCut flaws as exploited in the wild

The attacks on PaperCut print servers now have numbers attached. On 31 August 2026, CISA added two PaperCut NG and PaperCut MF vulnerabilities to its Known Exploited Vulnerabilities catalog, the list the agency maintains for bugs it has evidence are being used in real attacks.

The entries are CVE-2026-81578, described as a missing authentication for a critical function, and CVE-2026-82078, described as an unsafe reflection flaw. That is the whole of what CISA published: the agency lists the identifiers and the flaw classes, not an exploitation account, and its alert carries no severity scores.

The National Vulnerability Database record for CVE-2026-82078 rates it 9.4, critical. It describes unsafe dynamic class loading in the database connection utilities of PaperCut MF and NG, where the application instantiates database driver classes from configurable driver names without checking them against a list of approved drivers. The vendor's own advisory remains the authority on affected builds and fixed versions.

The bug that was already being used before it had a name

These identifiers close a gap that was open all last week. IntelFusions reported on PaperCut's emergency advisory and the confirmed customer intrusions behind it on 28 August, at which point no CVE had been assigned and no score published. Defenders who wanted to track the issue had nothing to track it by. They do now, which matters for anyone whose vulnerability scanner, ticketing system or insurance paperwork keys off CVE identifiers.

Patching is only half of what CISA is asking for

The KEV listing pulls federal civilian agencies into Binding Operational Directive 26-04, which requires them to prioritize rapid remediation of high-risk KEV entries on publicly exposed assets that grant total control of the asset after exploitation, while deferring action on lower-risk issues. The directive also sets expectations for when agencies must check whether threat actors compromised a system before the patch was applied.

That second half is the part every organization should copy. Exploitation of these flaws was being reported before the identifiers existed, so an internet-facing PaperCut server that was patched this week may still have been reached the week before. Patching closes the door; it does not tell you who already walked through it.

What to do now

Treat internet-exposed PaperCut NG and MF servers as the priority and apply the vendor's fixed builds, which its advisory specifies. CISA encourages all organizations, not only federal agencies, to prioritize KEV entries in their patching. Then go back through logs from before the patch went on and look for administrative activity, configuration changes to database connection settings and unexpected child processes on the print server. If the server was reachable from the internet at any point in the last fortnight, assume it was found by a scanner and check accordingly.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions