PaperCut Exploitation Escalates to Active Intrusions

Summary

CISA has added two vulnerabilities affecting PaperCut software, tracked as CVE-2026-82078 and CVE-2026-81578, to its Known Exploited Vulnerabilities (KEV) catalog. This addition indicates that these vulnerabilities are actively being exploited in the wild.

IFF Assessment

FOE

The active exploitation of PaperCut vulnerabilities and their addition to CISA's KEV catalog represent a significant threat to organizations using the software.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.

Defender Context

The inclusion of these PaperCut vulnerabilities in CISA's KEV catalog means that attackers are actively leveraging them for intrusions. Defenders must prioritize patching or implementing mitigations for affected systems to prevent compromise. Organizations should also conduct threat hunting to detect any signs of exploitation.

Read Full Story →