[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f33Z5rJqHGEB16uw3EENx9buBBGaBmjyM-fHh9BYySag":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"174d8de7-2bc5-47dd-9b29-9c54458a8c2d","active-papercut-exploits-highlight-critical-patching-urgency","5f0040ff-8a36-46d8-969a-891e252e3a1b","Active PaperCut Exploits Highlight Critical Patching Urgency","Two high-severity vulnerabilities in PaperCut NG\u002FMF (CVE-2026-81578 and CVE-2026-82078) are being actively exploited in the wild, prompting CISA to add them to its Known Exploited Vulnerabilities Catalog. Successful exploitation can grant attackers total control over affected assets, making these flaws particularly dangerous in enterprise and government environments where PaperCut is widely deployed for print management. Federal agencies are legally required under Binding Operational Directive 26-04 to remediate KEV-listed vulnerabilities within mandated timeframes. This incident underscores the critical importance of maintaining a proactive, prioritized vulnerability remediation program — especially for internet-facing or networked software systems.","**Immediate actions:**\n- Apply the latest PaperCut NG\u002FMF patches or vendor-recommended mitigations immediately, prioritizing internet-facing instances.\n- Restrict external access to PaperCut management interfaces using firewall rules or access control lists.\n- Cross-reference your asset inventory against CISA's KEV Catalog to identify all exposed systems requiring urgent remediation.\n\n**Long-term improvements:**\n- Establish a formal emergency patching procedure with defined SLAs for critical and actively exploited vulnerabilities.\n- Maintain a continuously updated inventory of all software assets to enable rapid impact assessment when new KEV entries are published.\n- Implement network segmentation to isolate print management servers from sensitive internal systems and the internet.\n\n**Detection measures:**\n- Deploy vulnerability scanning tools configured to alert on KEV-listed CVEs within 24 hours of catalog updates.\n- Monitor PaperCut server logs for anomalous authentication attempts, unexpected admin changes, or unusual API calls.\n- Subscribe to CISA KEV Catalog alerts to ensure your security team receives real-time notification of newly cataloged exploited vulnerabilities.",[12,13,14,15,16,17,18,19],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","CISA BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities","ITIL Change Management: Emergency Change Procedures","NIST CSF ID.RA-1: Asset Vulnerabilities are Identified and Documented","published","2026-08-31T16:21:33.326379+00:00","2026-08-31T16:21:33.023+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F08\u002F31\u002Fcisa-adds-two-known-exploited-vulnerabilities-catalog","cisa-adds-two-known-exploited-vulnerabilities-to-catalog-562c0e","CISA Adds Two Known Exploited Vulnerabilities to Catalog",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]