PaperCut NG/MF Unsafe Reflection Vulnerability Added to CISA’s Known Exploited Vulnerabilities Catalogue

CVE-2026-82078 allows arbitrary Java bytecode execution under the PaperCut server process and can be chained with a second actively exploited flaw.

AI-generated illustration depicting vulnerability for the story: PaperCut NG/MF Unsafe Reflection Vulnerability Added to CISA's Known Exploited Vulnerabilities Catalogue

Summary

  • CISA has added CVE-2026-82078, an unsafe reflection vulnerability in PaperCut NG/MF, to its Known Exploited Vulnerabilities catalogue.
  • The flaw permits attackers to manipulate system configuration parameters and execute arbitrary Java bytecode within the PaperCut server’s security context.
  • The vulnerability can be chained with CVE-2026-81578, which is also listed in the CISA KEV catalogue, amplifying the potential impact.
  • Federal agencies and organisations following BOD 26-04 must apply vendor-supplied mitigations or discontinue use of the product by 14 September 2026.
  • Asset owners should assess internet exposure of PaperCut instances and conduct forensic triage as directed by CISA guidance.

What Has Been Disclosed

CISA has formally added CVE-2026-82078 to its Known Exploited Vulnerabilities catalogue, confirming active exploitation of an unsafe reflection vulnerability in PaperCut NG and PaperCut MF. The vulnerability enables an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode that resides on the application classpath, doing so under the security context of the PaperCut server process itself.

The Chaining Risk

What elevates the severity here is the documented ability to chain CVE-2026-82078 with CVE-2026-81578, a separate vulnerability also listed in the CISA KEV catalogue. The sources do not detail the precise mechanics of that chain, but its inclusion in CISA’s required-action language is a clear signal that defenders should treat both vulnerabilities as a combined threat rather than evaluating them in isolation. Print management infrastructure running PaperCut is rarely at the top of the threat model for most organisations, which makes it an attractive pivot point.

Scope and Exposure

PaperCut NG and MF are widely deployed print management platforms found across enterprise, government, and education environments. CISA’s guidance specifically calls on stakeholders to evaluate the internet exposure of each affected asset. Instances accessible from the internet carry a materially higher risk profile than those isolated to internal networks, though lateral movement potential means internal-only deployments should not be deprioritised.

Compliance Obligations

For organisations bound by CISA’s Binding Operational Directive 26-04, the remediation deadline is 14 September 2026. BOD 26-04 applies both to on-premises deployments and to cloud-hosted services. Where mitigations cannot be applied in time, CISA’s guidance is unambiguous: discontinue use of the product. CISA has also referenced its Forensics Triage Requirements, indicating that affected organisations may be expected to preserve and examine artefacts to determine whether exploitation has already occurred.

What Remains Unknown

The source material does not identify the specific vendor patch version that addresses CVE-2026-82078, nor does it attribute exploitation activity to a particular threat actor or campaign. The attack vector details beyond the unsafe reflection mechanism are not described in the available sources. Organisations should consult PaperCut’s official security advisories directly for patch-level specifics.

Why it matters

Print management systems sit at the intersection of network access, user authentication, and file handling — and they are frequently overlooked during hardening reviews. An attacker who achieves code execution under the PaperCut server process inherits its network reach and permissions, which in many environments includes integrations with Active Directory and file shares. The chainable nature of this vulnerability with CVE-2026-81578 means a single unpatched PaperCut instance could become a reliable initial access or lateral movement vector. CISOs should confirm asset inventory, validate patch status, assess internet exposure, and initiate forensic triage on any instance that cannot be confirmed as uncompromised.

What to do now

  • Apply mitigations in accordance with PaperCut vendor instructions as directed by CISA’s KEV required action.
  • Ensure remediation or mitigation is in place by the CISA BOD 26-04 deadline of 14 September 2026.
  • Evaluate the internet exposure of every PaperCut NG/MF asset in your environment and apply heightened priority to internet-facing instances.
  • Follow applicable BOD 26-04 guidance for any cloud-hosted PaperCut deployments.
  • If mitigations cannot be applied, discontinue use of the product as directed by CISA.
  • Conduct forensic triage on PaperCut instances in accordance with CISA’s Forensics Triage Requirements to determine whether exploitation has already occurred.
  • Treat CVE-2026-82078 and CVE-2026-81578 as a combined risk and ensure both are addressed in remediation planning.

Sources