CiberLATAMbywhalemate

CISA adds active PaperCut flaws to KEV

CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA added three vulnerabilities already being exploited in real-world environments to its Known Exploited Vulnerabilities catalog: CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, and CVE-2026-82329 in JFrog Artifactory self-hosted. Researchers and technical advisories describe direct impact on exposed servers, with risk of remote code execution and escalation to administrator privileges.

CISA has added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in PaperCut NG/MF and JFrog Artifactory self-hosted. In PaperCut, the attack chain affects the Application Server web admin interface, and in Artifactory it can let a remote unauthenticated attacker obtain administrator privileges.

What was confirmed about PaperCut NG/MF?

CISA and several researchers confirmed active exploitation of CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF. Huntress said it verified attacks against CVE-2026-81578, described as a critical remote code execution flaw that allows system configuration changes without authentication, and also pointed to CVE-2026-82078 as part of the chain.

The available technical material adds that the vulnerable interface is the Application Server web interface, whose default listening ports are TCP 9191 and TCP 9192, according to Security Arsenal. WindowsForum said the flaws can be chained to achieve pre-authentication remote code execution on the server software, and that PaperCut's advisory reported confirmed customer incidents.

PaperCut issued an emergency bulletin for NG and MF, and told customers to restrict access to the Application Server web admin interface if it is exposed to the internet before applying patches.

What is known about JFrog Artifactory?

JFrog confirmed active exploitation of CVE-2026-82329 in Artifactory, a bypass-of-authentication flaw affecting self-hosted deployments. Based on the available coverage, a remote unauthenticated attacker can reach administrator privileges.

The Canadian Centre for Cyber Security published an advisory on the product and said vulnerable versions are earlier than 7.111.21. That same notice says CISA added CVE-2026-82329 to the KEV database on September 2, 2026. CiberPlaneta also reported that CISA added it to the catalog for active exploitation in Artifactory self-hosted, and watchTowr said it was already being used in the wild just days after JFrog released a patch.

Why does this matter for corporate environments?

PaperCut is used as a print management platform in companies, universities, and public agencies, according to CiberPlaneta, so active exploitation affects software with broad presence on internal networks. At the same time, Artifactory often sits in sensitive software repositories and self-managed deployments, and the reported authentication bypass leaves exposed systems where artifacts and dependencies are administered.

For organizations in Latin America that operate these tools, the picture combines internet exposure, actively exploited flaws, and direct paths to take control of servers or escalate privileges. CISA has already included them in KEV, which usually forces patching and access restrictions to the affected assets to the front of the queue.

Sources

View all