Our automated tracking framework flagged that CISA added CVE-2026-82078 (PaperCut NG/MF) to the Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-82078 by September 14, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-82078 |
| Vendor / product | PaperCut NG/MF |
| Vulnerability | PaperCut NG/MF Unsafe Reflection Vulnerability |
| CVSS base score | 9.1 |
| Added to KEV | August 31, 2026 |
| Days public before listing (NVD → KEV lag) | 3 |
| Federal patch deadline | September 14, 2026 |
| Known ransomware use | No |
How This Compares to PaperCut’s Track Record
This one was public for 3 days before CISA confirmed exploitation — longer than PaperCut’s 3-day median, a vulnerability that sat exploitable in the open.
| PaperCut in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 5 |
| Median lag (public → KEV listing) | 3 days |
| 0-day rate (exploited at or before disclosure) | 0% |
| Entries tied to known ransomware campaigns | 2 |
For perspective, the median across all 1686 tracked KEV entries is 266 days — PaperCut’s exploited vulnerabilities are flagged faster than the catalog average.
Other Recent PaperCut KEV Additions
The most recent PaperCut vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-81578 | NG/MF | August 31, 2026 | 3 | No |
| CVE-2023-27351 | NG/MF | April 20, 2026 | 1096 | ⚠️ Yes |
| CVE-2023-2533 | NG/MF | July 28, 2025 | 769 | No |
| CVE-2023-27350 | MF/NG | April 21, 2023 | 1 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2026-82078, an Unsafe Reflection Vulnerability in PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.1, this vulnerability presents a critical risk. Federal agencies must apply patches by September 14, 2026; all organizations should do so quickly. The high CVSS score indicates potential for significant impact, making internet-facing or easily accessible PaperCut NG/MF instances prime targets.
CVE-2026-82078 was added to the KEV catalog three days after its public disclosure. This tight window suggests that active exploitation began very quickly after public disclosure, and organizations should assume their systems may have been targeted or compromised if not patched immediately. There’s no known ransomware use with this CVE yet, but the rapid KEV listing warrants a proactive stance.
If you can’t apply the patch before the September 14 deadline, restrict network access to PaperCut servers to only essential ports and trusted IP addresses. Also, enhance monitoring for unusual activity on these systems. Review logs from the past three days for suspicious connections or process anomalies related to PaperCut instances to detect any potential post-exploitation activity.
Related Coverage
- PaperCut’s CVE-2026-81578 Was Exploited in 3 Days — Exactly Its Historical Median (September 2026)
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.