Cyber & AI intelligence
Wasteland.
Briefs indexed2354
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-81578 2026-08-31

PaperCut NG/MF Under Active Attack: CISA Adds CVE-2026-81578 to KEV

"CISA added CVE-2026-81578, a missing-authentication flaw in the PaperCut NG/MF web management interface, to its Known Exploited Vulnerabilities catalog on 2026-08-31, with a federal remediation deadline of 2026-09-14."

CISA added CVE-2026-81578, a missing-authentication flaw in the PaperCut NG/MF web management interface, to its Known Exploited Vulnerabilities catalog on 2026-08-31, with a federal remediation deadline of 2026-09-14.

What Is It

CVE-2026-81578 is an improper access control / missing authentication for critical function issue (CWE-306, with CWE-305 assigned as a secondary weakness) in the web management interface of PaperCut MF and PaperCut NG. Based on the public advisory language, the flaw appears to involve unauthenticated remote requests reaching administrative functions such that backend actions can be triggered before access validation completes; the vendor has not published a detailed technical breakdown, so the precise mechanism should be treated as provisional. The documented impact is integrity-focused: an unauthenticated remote attacker can modify certain system configurations.

NVD rates it CVSS 3.1 9.8 (CRITICAL): AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. A secondary CVSS 4.0 score from the vendor-side CNA puts it at 8.8 (HIGH), weighted toward integrity impact (VI:H). The two scores disagree on scope: NVD's vector asserts high confidentiality and availability impact alongside integrity, while the publicly described consequence, configuration modification, is integrity-only. Treat data exposure or service disruption as possible downstream effects of configuration tampering rather than as established primary impacts.

Why It Matters

CISA's KEV listing confirms active exploitation, and the accompanying SSVC decision point set marks exploitation as active and the vulnerability as automatable: yes, a designation that suggests attacks against exposed instances could be scripted at scale, though CISA does not publish the underlying evidence for that assessment. Attack requirements are none, no privileges, no user interaction.

CISA's KEV entry notes CVE-2026-81578 can be chained with CVE-2026-82078, which would turn configuration tampering into a stepping stone rather than an endpoint. A Metasploit Framework pull request (rapid7/metasploit-framework#21842) is referenced in the NVD record, indicating public tooling in motion; the PR's merge status and coverage should be checked directly before drawing conclusions about weaponization maturity. Known ransomware campaign use is currently listed as Unknown.

What's Vulnerable

PaperCut MF and PaperCut NG, per the vendor advisory, in all versions below 24.1.10, 25.0.13, and 26.0.5. NVD's CPE configuration covers the same three release trains:

Anything at or above the fixed release for its train is out of scope; everything below it, including older, unlisted branches that never received a patched build, should be treated as vulnerable.

Patch Status

Fixed versions are 24.1.10, 25.0.13, and 26.0.5. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidance. Due date: 2026-09-14.

Sources