CISA adds PaperCut CVEs to KEV after active intrusions escalate
Source headline: PaperCut Exploitation Escalates to Active Intrusions
Intelligence Summary
CISA added two PaperCut-related vulnerabilities, CVE-2026-82078 and CVE-2026-81578, to its KEV catalog. The update indicates the flaws have reached active intrusions. KEV inclusion means defenders should treat these issues as being exploited in real environments. The story highlights escalation from exploitation to intrusion activity. Users responsible for PaperCut deployments should check exposure and remediate the KEV-listed issues without delay. Apply available patches or mitigations for CVE-2026-82078 and CVE-2026-81578 now.
Recommended Action
Check your exposure to CVE-2026-82078 and apply the vendor fix once available. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.