Our automated tracking framework flagged that CISA added CVE-2026-81578 (PaperCut NG/MF) to the Known Exploited Vulnerabilities (KEV) catalog on September 1, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-81578 by September 14, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-81578 |
| Vendor / product | PaperCut NG/MF |
| Vulnerability | PaperCut NG/MF Missing Authentication for Critical Function Vulnerability |
| CVSS base score | 9.8 |
| Added to KEV | August 31, 2026 |
| Days public before listing (NVD → KEV lag) | 3 |
| Federal patch deadline | September 14, 2026 |
| Known ransomware use | No |
How This Compares to PaperCut’s Track Record
This one was public for 3 days before CISA confirmed exploitation — longer than PaperCut’s 3-day median, a vulnerability that sat exploitable in the open.
| PaperCut in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 5 |
| Median lag (public → KEV listing) | 3 days |
| 0-day rate (exploited at or before disclosure) | 0% |
| Entries tied to known ransomware campaigns | 2 |
For perspective, the median across all 1686 tracked KEV entries is 266 days — PaperCut’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent PaperCut KEV Additions
The most recent PaperCut vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-82078 | NG/MF | August 31, 2026 | 3 | No |
| CVE-2023-27351 | NG/MF | April 20, 2026 | 1096 | ⚠️ Yes |
| CVE-2023-2533 | NG/MF | July 28, 2025 | 769 | No |
| CVE-2023-27350 | MF/NG | April 21, 2023 | 1 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2026-81578, a PaperCut NG/MF vulnerability with a CVSS base score of 9.8, to its Known Exploited Vulnerabilities (KEV) catalog. This critical vulnerability demands immediate attention from security teams. The federal patch deadline is September 14, 2026, underlining the urgency for all organizations, especially those leveraging PaperCut NG/MF in their environments. The CVE was publicly known for only 3 days before its KEV listing, signaling rapid exploitation after disclosure.
Organizations running PaperCut NG/MF should patch before September 14, 2026. If you can’t patch by the deadline, restrict access to affected systems. This includes isolating them, applying strict network segmentation, and enhancing monitoring for unusual activity originating from or targeting PaperCut instances. Proactive threat hunting for signs of exploitation should also begin immediately to detect potential breaches. Though there’s no known ransomware use for this CVE, its critical severity and confirmed exploitation warrant swift action.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- WordPress’s CVE-2026-63030 Was Exploited in 4 Days — Well Under Its 420-Day Median (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.