Organizations should apply vendor patches for PaperCut NG/MF as soon as available. Federal agencies must prioritize rapid remediation per Binding Operational Directive (BOD) 26-04. All organizations are encouraged to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. Check systems for compromise before applying patches per BOD 26-04 requirements.
Quick answers
What is CVE-2026-82078?
Organizations should apply vendor patches for PaperCut NG/MF as soon as available. Federal agencies must prioritize rapid remediation per Binding Operational Directive (BOD) 26-04. All organizations are encouraged to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. Check systems for compromise before applying patches per BOD 26-04 requirements.
How severe is CVE-2026-82078?
high
Is CVE-2026-82078 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-82078 be mitigated?
Organizations should apply vendor patches for PaperCut NG/MF as soon as available. Federal agencies must prioritize rapid remediation per Binding Operational Directive (BOD) 26-04. All organizations are encouraged to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. Check systems for compromise before applying patches per BOD 26-04 requirements.
CVSS
—
Vendor
PaperCut
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
PaperCut NG/MF
Mitigation
Organizations should apply vendor patches for PaperCut NG/MF as soon as available. Federal agencies must prioritize rapid remediation per Binding Operational Directive (BOD) 26-04. All organizations are encouraged to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. Check systems for compromise before applying patches per BOD 26-04 requirements.
The Arctic Wolf Adversary Research Team has observed threat actors exploiting two newly disclosed PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to target educational institutions in the U.S. and Europe. The exploitation chain involves an authentication bypass followed by remote code execution, enabling command execution, reconnaissance, and credential theft. PaperCut NG and PaperCut MF products are affected. Patches have been released and administrators are urged to apply them immediately.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-81578 pertains to missing authentication for critical functions, and CVE-2026-82078 involves unsafe reflection in PaperCut NG/MF products. Both vulnerabilities pose significant risks to federal enterprise systems, particularly those publicly exposed. Binding Operational Directive 26-04 requires federal agencies to prioritize rapid remediation of these KEV Catalog vulnerabilities on publicly exposed assets.