CISA Adds Two Known Exploited Vulnerabilities to Catalog
Summary
CISA has added two new vulnerabilities, CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities pose significant risks and are a frequent attack vector for malicious actors.
IFF Assessment
The addition of new, actively exploited vulnerabilities to CISA's KEV Catalog signifies new threats that defenders must address, increasing their workload and potential risk.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
Organizations, particularly federal agencies, must prioritize the patching of these newly identified vulnerabilities affecting PaperCut NG/MF. Understanding the KEV Catalog and CISA's Binding Operational Directive (BOD) 26-04 is crucial for effective vulnerability management and risk-based remediation efforts to mitigate active threats.