Will PaperCut NG/MF zero-day be added to CISA KEV by Sept 2026?
[Auto-resolved by AI agent] CISA has officially added two PaperCut NG/MF vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-81578 (Missing Authentication for Critical Function) and CVE-2026-82078 (Unsafe Reflection). This directly satisfies the market resolution criteria. Additionally, Bleeping Computer confirms recent patched PaperCut zero-days are being used in data theft attacks.
Evidence: https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalogMarket Overview
AI GENERATEDPaperCut is warning of active zero-day exploitation in all versions of PaperCut NG and MF print management software (Bleeping Computer). Given the broad product range and confirmed exploitation, KEV addition is likely and material.
Primary SourceResolution Criteria
CISA KEV catalog entries mentioning CVE-2026-xxxxx (PaperCut NG/MF zero-day) or CISA public advisories confirming the vulnerability's addition to KEV