Exploited Known exploited (KEV) CVE-2026-81578

Missing authentication in PaperCut - chained with a second flaw it reaches arbitrary code execution (CVE-2026-81578)

PaperCut NG/MF Added to KEV Aug 31, 2026 Federal remediation due 2026-09-14

A missing authentication for critical function vulnerability in the print management software PaperCut NG/MF has been added to CISA's Known Exploited Vulnerabilities catalog. An unauthenticated remote attacker can modify certain system configurations.

Key facts

  • CVE IDCVE-2026-81578
  • Affected (vendor / product)PaperCut NG/MF
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-09-14 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Missing authentication for a critical function in PaperCut NG/MF lets an unauthenticated remote attacker modify certain system configurations.
  • CISA's description states explicitly that it can be chained with CVE-2026-82078.
  • That partner flaw manipulates configuration parameters to execute arbitrary Java bytecode.
  • What looks alone like a configuration change becomes remote code execution in combination.
  • Of the 1,687 KEV records this site holds as of 2026-09-02, 28 (1.7 per cent) name a chain in the description.
  • The due date is fourteen days after addition; among the 1,687, twenty-one days is most common at 1,025 and fourteen days covers 269.

1Changing settings is not where it ends

What this vulnerability alone permits is modifying certain system configurations. No files are taken and no code is run. Yet CISA's description states it can be chained with another vulnerability. That other flaw, CVE-2026-82078, manipulates configuration parameters to execute Java bytecode.

  1. 1The way inCertain system configurations can be modified without authentication (this flaw)
  2. 2The footholdThe modified configuration parameters become input to the next flaw
  3. 3ExecutionUnsafe reflection executes arbitrary Java bytecode
  4. 4ReachIt runs in the security context of the PaperCut server process

What looks alone like a configuration change becomes remote code execution in combination. Assessing severity one entry at a time misses this shape.

2Twenty-eight records name a chain

KEV records held by this site1,687CISA catalog of exploited vulnerabilities
Descriptions saying "chained with"281.7 per cent of the whole
Records including missing authentication (CWE-306)40CWEs run to 176 kinds overall

CISA names the partner in a chain inside the description for 28 of 1,687 records. Conversely, combinations not named cannot be read from the records. Attackers see reachable paths rather than individual flaws, so defenders have to think in combinations too.

3Fourteen days to remediate

The due date is set fourteen days after addition. Of the 1,687 records this site holds as of 2026-09-02, 269 carry a fourteen-day deadline, 1,025 carry twenty-one days - the most common - and 86 carry three days. The length varies with how far exploitation has spread and how hard the fix is.

Why it matters

Print management servers are reachable from many endpoints inside an organisation and tend to fall down the update queue. That a flaw limited to configuration change becomes code execution when combined with another in the same product exposes the weakness of prioritising by severity score alone. Where the partner in a chain is named, closing both at once is the judgement required.

FAQ

What can this flaw do on its own?
According to CISA's description, an unauthenticated remote attacker can modify certain system configurations.
Why does chaining matter?
Because being able to modify configurations becomes the foothold for another vulnerability, CVE-2026-82078, to execute arbitrary Java bytecode.
What is the deadline?
It was added to KEV on 31 August 2026 with a due date of 14 September 2026. Verify applicability with official vendor information and your own environment.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#CISA#PaperCut#missing authentication#vulnerability chaining#CWE-306
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.