PaperCut Vulnerabilities CVE-2026-81578 and CVE-2026-82078 Added to CISA KEV Database

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Advisory Date: August 28, 2026
Last Updated: August 31, 2026

Recent vulnerabilities have been identified in PaperCut products, specifically affecting versions of PaperCut MF and PaperCut NG. As of August 27, 2026, the following versions are impacted:

  • PaperCut MF
    • Prior to v24 Emergency Patch Release 2
    • Prior to v25 Emergency Patch Release 2
    • Prior to v26 Emergency Patch Release 2
  • PaperCut NG
    • Prior to v24 Emergency Patch Release 2
    • Prior to v25 Emergency Patch Release 2
    • Prior to v26 Emergency Patch Release 2

Exploitation Status

Open-source intelligence has indicated that vulnerabilities identified as CVE-2026-81578 and CVE-2026-82078 are currently being exploited in the wild. This raises significant concerns for organizations using the affected versions of PaperCut software.

Official Response and Recommendations

On August 31, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added both CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database. This inclusion highlights the urgency for users and administrators to take immediate action.

The Cyber Centre advises all users of PaperCut MF and PaperCut NG to review the advisory and apply any necessary updates as they become available. It is crucial to ensure that systems are running the latest versions to mitigate the risk of exploitation.

For further details and updates, please refer to the official advisory from the Cyber Centre: Cyber.gc.ca.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Media Streaming Devices with Open ADB Ports Expose Home Networks to Cyber Threats

Media streaming devices, particularly those with open Android Debug Bridge (ADB) ports, are exposing home networks to significant cybersecurity threats. According to a report...

Microsoft Warns of TerminalFix Campaign Using Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal...

Microsoft Security August 2026 Update Introduces Enhanced AI Management Tools and Threat Intelligence

As organizations increasingly integrate AI agents into their operations, the need for robust cybersecurity measures has never been more critical. The latest updates from...

TerminalFix Campaign Utilizes Fake CAPTCHA to Deploy Multi-Stage Attack and Reverse Tunnel Access

Microsoft Threat Intelligence has identified a new campaign named TerminalFix, a variant of ClickFix, which is targeting organizations across various sectors. This campaign employs...