CVE-2026-81578

Published Aug 28, 2026

Last updated 12 days ago

Exploit knownCVSS high 8.8
web application
Cloud
OT
SMTP
PaperCut MF
PaperCut NG

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-81578 describes an improper access control vulnerability found in the web management interface of PaperCut MF and PaperCut NG. This flaw allows unauthenticated remote requests, specifically those targeting administrative functions, to initiate backend actions before the system fully completes its access validation checks. The vulnerability, categorized as CWE-306 (Missing authentication for critical function), enables an unauthenticated remote attacker to modify certain system configurations. It has been observed to be actively exploited in the wild, often in conjunction with CVE-2026-82078, to achieve broader compromise.

Description
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Source
eb41dac7-0af8-4f84-9f6d-0272772514f4
NVD status
Analyzed
Products
papercut_mf, papercut_ng

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.8
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
Exploit added on
Aug 31, 2026
Exploit action due
Sep 14, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

eb41dac7-0af8-4f84-9f6d-0272772514f4
CWE-305

Social media

Hype score
Not currently trending
  1. We shared a one-off share of over 400 compromised PaperCut NG/MF instances (via CVE-2026-81578/CVE-2026-82078) observed by @GreyNoiseIO. IP data in our Compromised Website reporting for 2026-09-11, tagged 'papercut-compromise'. Dashboard Tree Map stats: https://t.co/8AQlPZIEgr

    @Shadowserver

    12 Sept 2026

    1761 Impressions

    9 Retweets

    11 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  2. Russian threat actors deployed hundreds of AI agents to automate exploitation of PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078. The campaign compromised 395 organizations across 48 countries while avoiding Russian and Chinese targets. Runtime segmentation could have

    @aviatrixtrc

    11 Sept 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Healthcare IT teams: patch PaperCut NG/MF NOW. AI agents helped compromise 440+ servers across 395 orgs in 48 countries. One school hit domain admin in 7 minutes. CVE-2026-81578 / CVE-2026-82078 https://t.co/kPaEPYPMoD

    @Techsico_IT

    11 Sept 2026

    50 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Prasówka 11.09 1. Wydano Ubuntu 24.04.5 LTS z jądrem 7.0 HWE. 2. Setki agentów AI przejęły 440 serwerów PaperCut w 395 firmach i 48 krajach (CVE-2026-81578 i CVE-2026-82078)

    @arkady86

    11 Sept 2026

    220 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Urgent update from PaperCut: NG/MF versions 26.0.5, 25.0.13, and 24.1.10 replace all emergency patches for two critical vulnerabilities (CVE-2026-81578 and CVE-2026-82078). Targets are actively exploiting these flaws using AI agents to breach authentication and run arbitrary http

    @dailytechonx

    11 Sept 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨Cisco FMCの脆弱性、ランサムウェアアクターや国家型ハッカーに悪用される:CVE-2026-20079、CVE-2026-20316 ⚠️数百体のAIエージェント使った攻撃でPaperCutの脆弱性が悪用され、395超の組織が侵害される:CVE-2026-81

    @MachinaRecord

    11 Sept 2026

    139 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  7. A likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek) to exploit CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, compromising 395 orgs in 26 seconds at campaign scale. #DFIR_Radar https://t.co/AYSBek61A9

    @DFIR_Radar

    10 Sept 2026

    166 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  8. GreyNoise says a likely Russian-speaking actor used hundreds of AI agents (OpenAI Codex and DeepSeek) to exploit PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078. The campaign hit 440 instances across 395 organizations in 48 countries, with first RCE in under four hours and

    @XavierRiveraX

    10 Sept 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. News: PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 chain to unauth RCE; active data theft. Install Emergency Patch Release 3 even after earlier fixes. Treat internet-facing unpatched servers as compromised.

    @snakeyesV1

    8 Sept 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🖨️PaperCut NG/MF Vulnerability Chain Exploited in Active Attacks CVE-2026-81578 and CVE-2026-82078 can be chained to bypass authentication, modify system settings, and execute arbitrary Java code on PaperCut servers. 🔎Criminal IP Asset Search found: ☑️Nearly 30,000

    @CriminalIP_US

    7 Sept 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🖨️ PaperCut NG/MF 취약점 공격 체인 분석​ PaperCut NG/MF에서 인증 우회 + 동적 클래스 로딩 취약점을 연계해 인증되지 않은 원격 공격자가 서버에서 임의 코드를 실행할 수 있는 공격 체인이 확인됐습니다.​ 이번

    @CriminalIP_KR

    7 Sept 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. #schwachstellen CVE-2026-81578: PaperCut NG/MF wird aktiv ausgenutzt – Konfiguration aus der Ferne änderbar #cisakev #cve202681578 #papercutngmf https://t.co/LyOapb9r01

    @cybsecuritynews

    7 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🔴 PaperCut attacks are moving beyond RCE Attackers exploiting CVE-2026-81578 and CVE-2026-82078 are now stealing credentials, targeting SAM/LDAP secret https://t.co/S75woKBEIU #CVE #CVE202681578 #CVE202682078 #PaperCut #CredentialTheft #RCE #CyberSecurity https://t.co/dL5cG

    @stem__shop

    6 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. PaperCut print servers (again, new wave) Chain: CVE-2026-81578 (auth bypass on the web UI) + CVE-2026-82078 (unsafe Java class load). Unauth RCE on PaperCut NG/MF. Vendor alert Aug 27. CISA KEV Aug 31. Federal due date Sep 14. Post-exploit seen: SimpleHelp RAT, Administrator17 ht

    @ichbinlucasv

    6 Sept 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. PaperCut flaws (CVE-2026-81578/82078) exploited for credential theft in education sector US/Europe. #CyberAttack #Education #RCE

    @chris_uk2026

    6 Sept 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2026-81578 and CVE-2026-82078, both in CISA KEV, are chained to bypass auth and execute code on PaperCut print servers targeting US 🇺🇸 and European education orgs. #DFIR_Radar https://t.co/1jDxevazBo

    @DFIR_Radar

    5 Sept 2026

    195 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🚨 CYBER — Nouvelle vague d’attaques contre PaperCut : des serveurs NG/MF compromis servent désormais à déployer des outils d’accès distant. Les attaquants exploitent CVE-2026-81578 et CVE-2026-82078, une chaîne permettant de contourner l’authentification puis d

    @ActuX_off

    5 Sept 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Attackers are actively exploiting PaperCut flaws (CVE-2026-81578 & CVE-2026-82078) for credential theft targeting schools and universities. Prioritize immediate patching and monitor for unauthorized accounts. #CyberSecurity #CyberAwareness

    @Lumideezy

    5 Sept 2026

    219 Impressions

    16 Retweets

    23 Likes

    3 Bookmarks

    8 Replies

    0 Quotes

  19. Arctic Wolf tracked unauth RCE in PaperCut via CVE-2026-81578 chained with CVE-2026-82078. The first flaw lets attackers drop files into /custom/ without creds; the second executes them directly through the web app. Hits began around 5 Sep 2026 against education targets in the US

    @SecureChap

    5 Sept 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🐦 🚨 Citrix NetScaler auth bypass (CVE-2026-19490, CVSS 9.3) is being actively exploited in the wild. PaperCut NG/MF pre-auth RCE chain (CVE-2026-81578/82078) hit CISA KEV, targeting schools & universities. Patch immediately. #infosec #CVE #0day

    @ita_ipo

    5 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨 PaperCut Açıkları Eğitim Kurumlarını Hedef Alıyor Saldırganlar CVE-2026-81578 ve CVE-2026-82078 açıklarını zincirleyerek PaperCut sunucularında kimlik doğrulamasını aşabiliyor, kod çalıştırabiliyor ve kimlik bilgilerini çalabiliyor. https://t.co/W1i4fA

    @KubbeSiber

    5 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an

    @OffensiveLab

    5 Sept 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Today's Pack Alert: Arctic Wolf has observed attackers actively exploiting critical PaperCut flaws (CVE-2026-81578, CVE-2026-82078) to steal SAM credentials and exfiltrate data. Technical details and indicators: https://t.co/Rxs7ffvB1B #PackAlert #ThreatResearch #ArcticWolf ht

    @AWNetworks

    4 Sept 2026

    114 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CRITICAL: CVE-2026-81578 in PaperCut NG/MF - Missing authentication allows unauthenticated remote attackers to modify system configs. Listed on CISA KEV. Can chain with CVE-2026-82078. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/VFZZL0RZY0

    @DFIR_Lab

    4 Sept 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 CRITICAL: CVE-2026-82078 - PaperCut NG/MF unsafe reflection flaw allows arbitrary Java bytecode execution. CISA KEV listed. Patch by Sept 14, 2026. Can be chained with CVE-2026-81578. #CVE #PatchNow #ThreatIntel https://t.co/h1n235ZZdN

    @DFIR_Lab

    4 Sept 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. PaperCut NG/MF: pre-auth RCE chain, exploited since Aug 26. CVE-2026-81578 (auth bypass, 8.8) + CVE-2026-82078 (unsafe class load, 9.4). Unauthenticated code on the App Server. Metasploit is public. CISA KEV Aug 31.

    @HardikDagha

    3 Sept 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. PaperCut zero-days (CVE-2026-82078 CVSS 9.4 + CVE-2026-81578) are being actively exploited. Three emergency patches in one week — if you stopped at patch 1 or 2, you're not done. Emergency Patch Release 3 (9/1) is cumulative. CISA KEV'd 8/31. https://t.co/DVzN6YWiGO

    @OpenVPN

    3 Sept 2026

    246 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  28. PaperCut NG/MF zero-days CVE-2026-82078 (CVSS 9.4) + CVE-2026-81578 chain to unauth RCE. CISA added both to KEV Sept 1. Emergency Patch Release 2 shipped because attackers bypassed the first fix. Huntress saw it in the wild. Print servers sit deep in your net. #ZeroDay #InfoSec

    @infrasecserv

    3 Sept 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. 🚨 [ACTIVE EXPLOITATION] — PAPERCUT SAYS A SECOND WAVE OF ATTACKS IS NOW HITTING UNPATCHED INTERNET-FACING SERVERS WITH MORE SOPHISTICATED POST-COMPROMISE ACTIVITY Attackers are exploiting: CVE-2026-81578 + CVE-2026-82078 and researchers have observed actors: DUMPING DATA

    @XQOPTRX

    3 Sept 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 CYBER — Deux failles critiques de PaperCut NG/MF sont activement exploitées. CVE-2026-81578 + CVE-2026-82078 peuvent être chaînées pour contourner l’authentification et exécuter du code à distance sur un serveur PaperCut. Les attaques ont évolué vers de vérita

    @ActuX_off

    3 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CVE-2026-81578 (CVSS 8.8) and CVE-2026-82078 are actively exploited zero-days in PaperCut NG/MF, chaining an auth bypass to unsafe Java class loading for pre-auth RCE as SYSTEM. Both are in CISA KEV; federal remediation deadline is September 14, 2026. - CVE-2026-81578 lets an ht

    @DFIR_Radar

    2 Sept 2026

    177 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  32. 🔒 #CyberSecurity CVE-2026-81578: PaperCut NG/MF Pre-Auth RCE Added to CISA KEV — Detection and R… "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-81578…" 🔗 https://t.co/oqEM5puUWw #CyberSecurity #ThreatIntel #cve #zeroday #patc

    @SecurityAr58409

    2 Sept 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. CISA KEV, Aug 31: two PaperCut NG/MF bugs. CVE-2026-81578 (no auth needed) chains with CVE-2026-82078 (unsafe reflection) for RCE. Federal remediation deadline Sep 14. Check if your print server is internet-facing.

    @Frankly_Alen

    2 Sept 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. DEEP DIVE — CVE-2026-81578: unauthenticated config-write in PaperCut NG/MF, chained to CVE-2026-82078 for SYSTEM-level RCE. KEV-listed, exploited in the wild. If it reports 25.0.12 you can still be on the bypassable build. Check the build number. https://t.co/0nO5wvgh4d

    @DailyCVEBrief

    2 Sept 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. PaperCut NG/MF zero-days CVE-2026-82078 (CVSS 9.4) + CVE-2026-81578 chain to unauth RCE. CISA added both to KEV Sept 1. Emergency Patch Release 2 shipped because attackers bypassed the first fix. Huntress saw it in the wild. Print servers sit deep in your net. #ZeroDay #InfoSec

    @infrasecserv

    2 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. CVE-2026-82078 (CVSS 9.4) chained with CVE-2026-81578 (CVSS 8.8) gives pre-auth RCE on PaperCut NG/MF; first patch was bypassed, requiring Emergency Patch Release 2. #DFIR_Radar https://t.co/09Ikj4rwUH

    @DFIR_Radar

    2 Sept 2026

    183 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  37. PaperCut NG ve MF için sıfır-gün zafiyet zinciri: CVE-2026-81578 ve CVE-2026-82078 aktif istismarda, CISA KEV emri https://t.co/xZ34YsJrOf #CISAKEV #CVE202681578 #CVE202682078

    @EnvanterMedya

    2 Sept 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Print servers are not “low risk”, PaperCut just proved it. CVE-2026-81578 + CVE-2026-82078 (PaperCut NG/MF): unauth config change chained to unsafe reflection → RCE. Now on CISA’s KEV list. Due date 14 Sep. Attacks already moved from recon to hands-on-keyboard + RATs.

    @PadhiyarRushi

    2 Sept 2026

    130 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to compromise PaperCut print servers and dump database tables for data theft. TRC analysis shows threat actors pivoted from compromised servers to access internal database systems across the network. Runtime segmentation

    @aviatrixtrc

    2 Sept 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. PaperCutのゼロデイ 脆弱性、CISAがCVE-2026-81578/82078をKEV追加 Huntressが認証前RCEを再現 https://t.co/8HBQUqbdiS #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    @securityLab_jp

    2 Sept 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Security Bulletin: PaperCut NG/MF vulnerabilities CVE-2026-82078 (9.4) and CVE-2026-81578 (8.8) are actively exploited. Install Emergency Patch Release 2 immediately, even if the original patch was applied. #ThreatIntel #RedLeggCTI https://t.co/A5QL4NTqLk

    @RedLegg

    1 Sept 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. PaperCut MF/NG incidents: At least 204 instances found on 2026-08-31 still vulnerable to CVE-2026-82078/CVE-2026-81578 RCE that is exploited in the wild. Make sure to check for compromise & patch. Top affected: US (60). Dashboard World Map view stats: https://t.co/ysTAPux1X6

    @Shadowserver

    1 Sept 2026

    1640 Impressions

    5 Retweets

    5 Likes

    1 Bookmark

    1 Reply

    1 Quote

  43. PaperCut NG/MF: attackers chained CVE-2026-81578 + CVE-2026-82078. No login. Defused saw Derby DB dumps. CISA added both to KEV Aug 31. #cybersecurity #infosec #CISA #KEV #PaperCut

    @Caldura7

    1 Sept 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. PaperCut Zero-Days Exploited in Active Data Theft Attacks Attackers are abusing PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078 to bypass authentication and dump embedded… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #papercut http

    @HotaSamit

    1 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. CISA added PaperCut CVE-2026-82078 and CVE-2026-81578 to KEV after active intrusions. Patch now and assume exposed, unpatched systems are compromised. Apex Cyber Guardians can help. #CyberSecurity https://t.co/geC10FZev0

    @apcyberguard

    1 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. PaperCut CVE-2026-82078 and CVE-2026-81578 are now on CISA's KEV list and being used in active data theft campaigns. Print management servers sitting inside your AVD or VDI network segment with no micro-segmentation are a lateral movement risk here, not just a print risk. Patch

    @markovichio

    1 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  47. 🚨 Patch Now | September 1, 2026 Bringing these critical vulnerabilities to your attention: 🔴 Citrix NetScaler ADC/Gateway(CVE-2026-8452, CVSS 8.8) 🟠 Microsoft Windows AFD.sys (CVE-2026-68820, CVSS 7.0) 🔴 PaperCut NG/MF (CVE-2026-81578 & CVE-2026-82078, CVSS 8.

    @CERT_UG

    1 Sept 2026

    115 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  48. Η CISA επιβεβαίωσε ενεργή εκμετάλλευση δύο ευπαθειών στο PaperCut (CVE-2026-82078, CVE-2026-81578). Επιχειρήσεις και δημόσιοι φορείς που το χρησιμοποιούν πρέπει να προχωρήσ

    @imetrixgr

    1 Sept 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. PaperCut NG/MF zero-days (CVE-2026-82078, CVE-2026-81578) are now in CISA KEV and driving data theft, while JFrog Artifactory auth bypass CVE-2026-82329 is under active exploitation days after disclosure. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1RTfujYNTK

    @itsalreadywhen

    1 Sept 2026

    69 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  50. On Aug. 31, 2026, CISA added CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalog; Sept. 1 reports tied scanning to real intrusions. Chained, the PaperCut flaws allow unauthenticated configuration changes and server-context code execution.

    @Securehup

    1 Sept 2026

    53 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations