CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. These vulnerabilities pose significant risks and are a frequent attack vector for malicious actors.

IFF Assessment

FOE

The addition of new, actively exploited vulnerabilities to CISA's KEV Catalog signifies new threats that defenders must address, increasing their workload and potential risk.

Severity

CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, particularly federal agencies, must prioritize the patching of these newly identified vulnerabilities affecting PaperCut NG/MF. Understanding the KEV Catalog and CISA's Binding Operational Directive (BOD) 26-04 is crucial for effective vulnerability management and risk-based remediation efforts to mitigate active threats.

Read Full Story →