Papercut: 2 Actively-Exploited Flaws Added to CISA KEV
CISA has added two actively-exploited vulnerabilities affecting Papercut products to its Known Exploited Vulnerabilities Catalog, underscoring the immediate threat these flaws pose to organizations.

Key findings
- Two Papercut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, are now in CISA's KEV catalog.
- Both flaws are confirmed to be under active exploitation by threat actors.
- No direct ransomware association has been reported for these specific CVEs.
- Organizations must apply patches or mitigations for affected Papercut products immediately.
- Federal agencies must remediate these vulnerabilities by February 27, 2027.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert, adding two Papercut vulnerabilities to its authoritative Known Exploited Vulnerabilities (KEV) Catalog. This inclusion signifies that these flaws, identified as CVE-2026-81578 and CVE-2026-82078, have been confirmed to be under active exploitation in real-world attacks. The KEV catalog serves as a critical resource for federal agencies and is increasingly adopted by private sector organizations to prioritize and address the most dangerous security weaknesses.
The newly cataloged vulnerabilities are:
- **CVE-2026-81578**: This flaw impacts Papercut products and has been observed in active exploitation campaigns.
- **CVE-2026-82078**: Also affecting Papercut, this vulnerability is similarly being actively leveraged by threat actors.
At present, there is no indication that these specific vulnerabilities are directly associated with ransomware campaigns. However, their active exploitation status means they could serve as initial access vectors for various malicious activities, including data exfiltration, system compromise, or the eventual deployment of ransomware.
Organizations utilizing Papercut products must treat these vulnerabilities with the highest priority. CISA's binding operational directive mandates that federal civilian executive branch agencies remediate KEV entries by a specific deadline, which for these flaws is February 27, 2027. All organizations, regardless of sector, are strongly advised to apply available patches or mitigation strategies immediately to prevent potential compromise. Proactive patching and robust vulnerability management are essential to defend against these actively exploited threats.