What CISA Just Added, and Why It Was Already Too Late
CISA added two PaperCut vulnerabilities to its Known Exploited Vulnerabilities catalog on 31 August 2026, confirming active exploitation in the wild.
| Metric | CVE-2026-81578 | CVE-2026-82078 |
|---|---|---|
| CVSS 4.0 score | 8.8 (High) | 9.4 (Critical) |
| Vulnerability type | Missing authentication for a critical function | Unsafe reflection (unsafe dynamic class loading) |
| What it enables | Unauthenticated access to change system configuration | Arbitrary Java code execution on the server |
CVE-2026-81578 lets an unauthenticated attacker reach PaperCut's web management interface and change system configuration, and CVE-2026-82078 turns that access into arbitrary Java code execution on the server.
Both flaws were already being exploited as zero-days before PaperCut published any fix, so an organization patching on its normal monthly cycle had already been compromised by the time a fix existed.
How the Attack Chain Actually Works
An attacker starts with CVE-2026-81578, the missing-authentication flaw, to reach the PaperCut Application Server's configuration interface without any credentials or user interaction.
From inside that interface the attacker triggers CVE-2026-82078, an unsafe dynamic class loading bug in the database connection utilities, which loads and runs arbitrary Java code of the attacker's choosing.
The result is full remote code execution on the print server, and it doesn't require a stolen password, a phishing email, or an employee clicking anything.
Why a Federal Deadline Undersells Your Real Exposure
Binding Operational Directive 26-04 sets 14 September 2026 as the date US federal civilian agencies must finish remediating these two CVEs.
That deadline is an administrative artifact of US government contracting; it says nothing about when the danger began for anyone else running the same software.
The exploitation that matters started in late August, days after PaperCut's own bulletin and weeks before any government due date, and it started the same way in Frankfurt, Rotterdam, and Milan as in Washington.
The Second Patch Nobody's Talking About
PaperCut released its first emergency patch for NG/MF versions 25 and 26 on 28 August 2026, four days before the KEV listing landed.
Within days the vendor followed with an Emergency Patch Release 2 for the same v25 and v26 branches, adding hardening the first patch didn't include, plus a separate Release 2 for the older v24 branch.
An organization that stopped at the first patch has closed one entry route while leaving the extra hardening in Release 2 unapplied, and that gap matters given how fast the vendor itself had to revise its own fix.
What to Do This Week
Every organization running PaperCut NG or MF should check its installed version against PaperCut's security bulletin today, not at the next scheduled maintenance window.
Confirm the server is on the Release 2 hardened build for v25/v26, or the v24 Release 2 build, since the initial 28 August patch alone isn't the finished fix.
Under NIS2, many mid-size EU companies now carry their own duty-of-care and incident-reporting obligations, and a breach traced to an unpatched KEV-listed flaw is hard to defend as reasonable care afterward. National authorities across the region, including the UK's NCSC, tell operators to judge urgency from the vendor's own advisory.
Servola Journal
We do this for everyone trying to keep up with what technology is doing to our lives. The people who build it, and the people it happens to. The Servola Journal exists so that what we learn belongs to all of them.
Nobody pays us for this. No ads, no paywall, free to everyone. We just believe that understanding what's happening to all of us shouldn't depend on who can afford to pay for it.
If it gave you something today, tell us to keep going. Follow us, leave a like, or write a positive comment. We read every one, and they are what keeps us going.
Read next: Gunra Ransomware Runs on Fortinet Bugs Patched in 2025 | Clearing the Attacker Also Clears Your Logic



