Executive Summary
In August 2026, CISA added two critical PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. CVE-2026-81578 involves missing authentication for critical functions, while CVE-2026-82078 represents an unsafe reflection vulnerability. These vulnerabilities affect PaperCut's widely-deployed print management software used across enterprise environments. The addition to KEV indicates threat actors are actively leveraging these flaws to compromise federal and private sector organizations, potentially leading to unauthorized system access and lateral movement.
This incident highlights the continuing evolution of attack vectors targeting enterprise infrastructure software, particularly as organizations increasingly rely on cloud-hybrid print management solutions that bridge on-premises and cloud environments.
Why This Matters Now
Print management systems like PaperCut are often overlooked in security assessments but provide attackers with deep network access and potential pathways to sensitive document workflows, making rapid patching critical as hybrid work models expand.
Attack Path Analysis
Attackers exploited two PaperCut NG/MF vulnerabilities (CVE-2026-81578 missing authentication and CVE-2026-82078 unsafe reflection) to gain initial access to enterprise networks. Following exploitation, attackers escalated privileges through reflection-based code execution, moved laterally across network segments to access cloud workloads, established command and control channels, exfiltrated sensitive documents and user data, and potentially disrupted printing operations or deployed additional payloads for sustained impact.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-81578 missing authentication vulnerability in publicly exposed PaperCut NG/MF systems to gain unauthorized access to critical functions
Related CVEs
CVE-2023-27350
CVSS 9.8Missing authentication for critical function vulnerability in PaperCut NG/MF allows unauthenticated remote code execution.
Affected Products:
PaperCut Software International PaperCut NG – < 22.0.9
PaperCut Software International PaperCut MF – < 22.0.9
Exploit Status:
exploited in the wildCVE-2023-27351
CVSS 7.5Unsafe reflection vulnerability in PaperCut NG/MF allows authenticated remote code execution through crafted input.
Affected Products:
PaperCut Software International PaperCut NG – < 22.0.9
PaperCut Software International PaperCut MF – < 22.0.9
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Process Injection
Valid Accounts
External Remote Services
Command and Scripting Interpreter
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Patches
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Monitoring and Vulnerability Assessments
Control ID: 500.16
CISA ZTMM 2.0 – Application Layer Security Controls
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face mandatory rapid remediation under BOD 26-04 for PaperCut vulnerabilities enabling authentication bypass and unsafe reflection exploitation.
Higher Education/Acadamia
Educational institutions using PaperCut print management systems vulnerable to critical authentication bypass and reflection attacks requiring immediate patching.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance risks from PaperCut vulnerabilities potentially exposing protected health information through authentication bypass attacks.
Financial Services
Financial institutions must prioritize PaperCut patches to prevent authentication bypass vulnerabilities that could compromise sensitive financial data and systems.
Sources
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- PaperCut Security Bulletin - Critical Vulnerabilities May 2023https://www.papercut.com/kb/Main/Security-Bulletin-May-2023Verified
- NVD - CVE-2023-27350 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-27350Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this PaperCut vulnerability exploitation by constraining lateral movement across network segments and limiting access to cloud workloads through segmentation controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise may still occur through the PaperCut vulnerability, but subsequent access to cloud-native workloads and services would likely be constrained through identity-aware segmentation policies
Control: Zero Trust Segmentation
Mitigation: Privilege escalation within the PaperCut system may proceed, but the scope of elevated access would likely be constrained to the segmented environment without broader network privileges
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely encounter significant constraints as east-west traffic enforcement blocks unauthorized communication paths between network segments and cloud workloads
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely face detection and potential blocking through comprehensive traffic visibility and policy enforcement across multicloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely encounter restrictions through egress policy enforcement that monitors and controls outbound data flows to unauthorized external destinations
While printing operations may still face disruption, the overall impact scope would likely be reduced through segmentation controls that limit access to critical business systems and cloud resources
Impact at a Glance
Affected Business Functions
- Print Management Services
- Document Processing
- Network Infrastructure
- IT Asset Management
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of print logs, user credentials, and document metadata stored within PaperCut systems. Risk of lateral movement to connected network resources through compromised print management infrastructure.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate print management systems from critical cloud workloads and prevent lateral movement
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration from compromised systems to external destinations
- • Enable Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests targeting vulnerable applications
- • Utilize Inline IPS (Suricata) with current threat signatures to identify and block known exploit patterns for CVE-2026-81578 and CVE-2026-82078
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal PaperCut system behavior and alert on exploitation attempts



