Threat+Constellation
Live UTC
← Incidents
INCIDENT 364Exploited vulnerabilityLOW / UNDER REVIEWSourced

CVE-2026-82078 added to CISA KEV: PaperCut NG/MF Unsafe Reflection Vulnerability

PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578. Product: PaperCut NG/MF. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follo…

Last evidence update
31 AUG 2026 · 12:00 UTC
Source count
3
Status
reported
GovernmentCVE-2026-82078CVE-2026-81578
Observation history

How this record has evolved as evidence accumulated.

01 SEP · 05:22 UTC
Second independent source
01 SEP · 05:22 UTC
Initial report
01 SEP · 05:22 UTC
Second independent source
Evidence