Jessica Entwistle
September 1 2026
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting PaperCut NG/MF print management software to its Known Exploited Vulnerabilities catalog, based on evidence of active exploitation. The vulnerabilities, tracked as CVE-2026-81578 (missing authentication for critical function) and CVE-2026-82078 (unsafe reflection), are now being exploited in the wild according to CISA's advisory. SecurityWeek reports that exploitation has escalated to active intrusions, meaning attackers are moving beyond initial access to conduct further malicious activity inside victim networks. PaperCut is widely deployed across enterprise, education and healthcare environments in the UK and internationally to manage printing, scanning and document workflows, making these vulnerabilities a significant risk for organisations that have not yet applied available patches.
For UK organisations using PaperCut, this represents an immediate operational risk. Print management systems often have broad network access, integration with Active Directory, and visibility across user activity, making them a valuable target for attackers seeking to establish persistence, move laterally or exfiltrate data. The progression from vulnerability disclosure to active exploitation and intrusion highlights how quickly attackers operationalise new weaknesses in widely deployed enterprise software. Print infrastructure is often overlooked in security reviews because it is perceived as low-risk or non-critical, but modern print management systems have privileged access, handle sensitive documents, and can provide attackers with a foothold for further compromise. Organisations that have not yet patched these vulnerabilities should treat this as a priority, and those unsure of their patch status should verify immediately. This is also a reminder that print management, like any other enterprise system, requires the same patch management discipline, monitoring and access controls as more obviously critical infrastructure.
UK organisations should verify whether PaperCut NG/MF is deployed, confirm that patches for CVE-2026-81578 and CVE-2026-82078 have been applied, and ensure print management systems are included in regular vulnerability scanning and patch management cycles. IT teams should review whether print infrastructure is monitored for unusual authentication attempts, lateral movement or data exfiltration, and whether access controls are appropriately configured to limit exposure. Organisations should also consider whether print management systems are included in incident response plans, and whether security teams have visibility into the configuration and network access of these systems. Print infrastructure is easy to overlook, but it often has privileged access and should be managed with the same rigour as any enterprise application.
Source: CISA