type: vulnerability ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [cve, papercut, ng, mf, authentication, kev, actively-exploited] ยท confidence: high ยท severity: critical ยท affected_sectors: [Government, Education, Financial Services] ยท au_impact: true
CVE-2026-81578
CVE-2026-81578 is a missing-authentication-for-critical-function vulnerability in PaperCut NG/MF, added to CISA's Known Exploited Vulnerabilities (KEV) catalogue on 31 August 2026.
PaperCut is an Australian print-management vendor, and its NG/MF products are widely deployed across Australian government, education and financial-services organisations. The KEV addition follows active exploitation reported earlier in the week and a second emergency patch released by PaperCut after the first fix was bypassed. Organisations should apply the vendor's patched release immediately and confirm PaperCut NG/MF instances are not exposed to the internet without authentication controls.