Our automated tracking framework flagged that CISA added CVE-2026-81578 (PaperCut NG/MF) to the Known Exploited Vulnerabilities (KEV) catalog on September 1, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-81578 by September 14, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-81578
Vendor / product PaperCut NG/MF
Vulnerability PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
CVSS base score 9.8
Added to KEV August 31, 2026
Days public before listing (NVD → KEV lag) 3
Federal patch deadline September 14, 2026
Known ransomware use No

How This Compares to PaperCut’s Track Record

This one was public for 3 days before CISA confirmed exploitation — longer than PaperCut’s 3-day median, a vulnerability that sat exploitable in the open.

PaperCut in the CISA KEV catalog Value
Tracked KEV entries 5
Median lag (public → KEV listing) 3 days
0-day rate (exploited at or before disclosure) 0%
Entries tied to known ransomware campaigns 2

For perspective, the median across all 1686 tracked KEV entries is 266 days — PaperCut’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent PaperCut KEV Additions

The most recent PaperCut vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-82078 NG/MF August 31, 2026 3 No
CVE-2023-27351 NG/MF April 20, 2026 1096 ⚠️ Yes
CVE-2023-2533 NG/MF July 28, 2025 769 No
CVE-2023-27350 MF/NG April 21, 2023 1 ⚠️ Yes

What This Means for Defenders

CISA has added CVE-2026-81578, a PaperCut NG/MF vulnerability with a CVSS base score of 9.8, to its Known Exploited Vulnerabilities (KEV) catalog. This critical vulnerability demands immediate attention from security teams. The federal patch deadline is September 14, 2026, underlining the urgency for all organizations, especially those leveraging PaperCut NG/MF in their environments. The CVE was publicly known for only 3 days before its KEV listing, signaling rapid exploitation after disclosure.

Organizations running PaperCut NG/MF should patch before September 14, 2026. If you can’t patch by the deadline, restrict access to affected systems. This includes isolating them, applying strict network segmentation, and enhancing monitoring for unusual activity originating from or targeting PaperCut instances. Proactive threat hunting for signs of exploitation should also begin immediately to detect potential breaches. Though there’s no known ransomware use for this CVE, its critical severity and confirmed exploitation warrant swift action.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.