type: vulnerability ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [cve, papercut, ng, mf, unsafe-reflection, kev, actively-exploited] ยท confidence: high ยท severity: critical ยท affected_sectors: [Government, Education, Financial Services] ยท au_impact: true
CVE-2026-82078
CVE-2026-82078 is an unsafe-reflection vulnerability in PaperCut NG/MF, added to CISA's Known Exploited Vulnerabilities (KEV) catalogue on 31 August 2026 alongside CVE-2026-81578.
Both flaws affect the Australian vendor's print-management products, which are widely deployed in Australian government, education and financial-services environments. Their KEV addition reflects confirmed in-the-wild exploitation and follows PaperCut's release of a second emergency patch earlier in the week after an initial fix was bypassed. Operators should apply the patched release immediately and remove any internet exposure of the administration interface.