official data
CISA adds PaperCut NG/MF flaws to KEV — federal fix by Sep 14
On 31 August 2026, CISA announced it had added two vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2026-81578 (PaperCut NG/MF Missing Authentication for Critical Function) and CVE-2026-82078 (PaperCut NG/MF Unsafe Reflection). Both carry KEV catalog date added 2026-08-31 and due date 2026-09-14 under Binding Operational Directive (BOD) 26-04 prioritization for Federal Civilian Executive Branch agencies on publicly exposed high-risk assets. CISA notes these vulnerability types are a frequent attack vector and pose significant risks to the federal enterprise.
Key facts
- Alert date
- August 31, 2026
- CVE-2026-81578
- PaperCut NG/MF Missing Authentication for Critical Function — unauthenticated remote attacker can modify certain system configurations; chainable with CVE-2026-82078
- CVE-2026-82078
- PaperCut NG/MF Unsafe Reflection — attacker can manipulate configuration and execute arbitrary Java bytecode on the application classpath under PaperCut server process context; chainable with CVE-2026-81578
- KEV dates
- Date Added 2026-08-31; Due Date 2026-09-14 for both
- Directive
- BOD 26-04 prioritization for FCEB on publicly exposed high-risk assets; CISA encourages all organizations to prioritize KEV remediation
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
CISA alert, August 31, 2026
Note
This note restates CISA’s public alert and KEV catalog fields. It is not an exploit guide and does not include proof-of-concept steps.
PaperCut’s vendor advisory is linked from the KEV catalog notes. Organizations should follow vendor mitigations and applicable BOD 26-04 guidance.
Why it matters
Brand-new Aug 31 CISA KEV addition with active-exploitation evidence and a Sep 14 federal due date — AI/cyber governance signal distinct from Siemens AA26-231A and the House CAISI bill.
Sources
Official data. Not a forecast.