On August 31, 2026, CISA added both PaperCut print management flaws to its Known Exploited Vulnerabilities catalog and set a remediation deadline of September 14, 2026 for federal civilian agencies. CVE-2026-81578, catalogued as a missing authentication for critical function vulnerability and rated CVSS 8.8, allows an unauthenticated remote attacker to modify certain system configuration settings in PaperCut NG and MF. CVE-2026-82078, catalogued as an unsafe reflection vulnerability and rated CVSS 9.4, allows an attacker to manipulate configuration parameters and execute arbitrary Java bytecode already present on the application classpath, running under the security context of the PaperCut server process. Chained, the first bypasses authentication and the second delivers code execution, and all versions of PaperCut NG and PaperCut MF are affected. PaperCut published a second emergency security update after researchers demonstrated multiple ways to bypass the initial fixes; Huntress reported a bypass of the first patch set, and watchTowr stated it identified further bypasses affecting the latest fully patched version. The Canadian Centre for Cyber Security has issued its own advisory, AV26-858, now at Update 2. A KEV listing is a meaningful change in status rather than a formality: it means CISA has evidence the flaws are being used against real targets, and it converts the question from whether to patch into when. Observed post-exploitation activity has so far looked like reconnaissance, including Base64-encoded commands such as "whoami & ver" and a Java class file that fingerprints the machine, writes a directory listing to a file named Udydn.out, and then deletes that file along with server.log and derby.log.
Recommended action:Remove public internet exposure first and treat that as the control you are actually relying on, because researchers have reported bypasses affecting even the fully patched version. Put the PaperCut Application Server behind a VPN or restrict its web interface to trusted internal addresses, then apply the second emergency patch — and if you applied the first emergency patch last week, you are not finished, because that one has a published bypass. Watch for further PaperCut bulletins rather than treating the matter as closed. Municipal, government, and healthcare organizations should adopt the September 14 federal deadline as their own internal target; it is a defensible date to put in front of leadership, and it is the date an auditor or a cyber insurer will likely reference if this comes up later. Then hunt, on the assumption that the logs may not be trustworthy. The attacker tooling deletes server.log and derby.log after running, so an unexplained gap, a truncated file, or a missing period of activity is itself evidence worth escalating. Look for the log entry watchTowr highlighted — "Database error looking up cardID: VALUES CAST" — for unusual activity involving the pc-app.exe process, and for any file named Udydn.out or stray .class files under the installation directory. Preserve copies of the logs off the server before anything rotates. The reason this matters in a hospital or a municipality is what the server connects to rather than what it does. PaperCut typically runs on Windows with elevated service privileges, authenticates users against Active Directory, and often shares a domain with clinical or financial systems, which makes it a pivot rather than an endpoint. Print queues also routinely carry documents containing ePHI — face sheets, orders, discharge paperwork, lab results — so a confirmed compromise is a security incident under 45 CFR §164.308(a)(6) and should start your documented response process, including rotating the PaperCut service account and any Active Directory credentials it holds. If you do not know whether PaperCut runs in your environment, ask your IT provider today.
Sources: CISA alert — two vulnerabilities added to the Known Exploited Vulnerabilities Catalog (August 31, 2026), CISA KEV entries for CVE-2026-81578 and CVE-2026-82078, PaperCut urgent security advisory and second emergency patch, Canadian Centre for Cyber Security advisory AV26-858 Update 2, Huntress research, watchTowr Labs research, Rapid7, BleepingComputer.