Our automated tracking framework flagged that CISA added CVE-2026-82078 (PaperCut NG/MF) to the Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-82078 by September 14, 2026 — a 14-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-82078
Vendor / product PaperCut NG/MF
Vulnerability PaperCut NG/MF Unsafe Reflection Vulnerability
CVSS base score 9.1
Added to KEV August 31, 2026
Days public before listing (NVD → KEV lag) 3
Federal patch deadline September 14, 2026
Known ransomware use No

How This Compares to PaperCut’s Track Record

This one was public for 3 days before CISA confirmed exploitation — longer than PaperCut’s 3-day median, a vulnerability that sat exploitable in the open.

PaperCut in the CISA KEV catalog Value
Tracked KEV entries 5
Median lag (public → KEV listing) 3 days
0-day rate (exploited at or before disclosure) 0%
Entries tied to known ransomware campaigns 2

For perspective, the median across all 1686 tracked KEV entries is 266 days — PaperCut’s exploited vulnerabilities are flagged faster than the catalog average.

Other Recent PaperCut KEV Additions

The most recent PaperCut vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-81578 NG/MF August 31, 2026 3 No
CVE-2023-27351 NG/MF April 20, 2026 1096 ⚠️ Yes
CVE-2023-2533 NG/MF July 28, 2025 769 No
CVE-2023-27350 MF/NG April 21, 2023 1 ⚠️ Yes

What This Means for Defenders

CISA has added CVE-2026-82078, an Unsafe Reflection Vulnerability in PaperCut NG/MF, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.1, this vulnerability presents a critical risk. Federal agencies must apply patches by September 14, 2026; all organizations should do so quickly. The high CVSS score indicates potential for significant impact, making internet-facing or easily accessible PaperCut NG/MF instances prime targets.

CVE-2026-82078 was added to the KEV catalog three days after its public disclosure. This tight window suggests that active exploitation began very quickly after public disclosure, and organizations should assume their systems may have been targeted or compromised if not patched immediately. There’s no known ransomware use with this CVE yet, but the rapid KEV listing warrants a proactive stance.

If you can’t apply the patch before the September 14 deadline, restrict network access to PaperCut servers to only essential ports and trusted IP addresses. Also, enhance monitoring for unusual activity on these systems. Review logs from the past three days for suspicious connections or process anomalies related to PaperCut instances to detect any potential post-exploitation activity.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.