Security & Risk6 minNewsroom

CISA Sets September 14 Deadline for PaperCut After Second Emergency Patch Fails to Bypass watchTowr

Mão fixa etiqueta vermelha de urgência sobre calendário de patches impresso em mesa de sala de operações de segurança.

The U.S. agency added CVE-2026-82078 (CVSS 9.4) and CVE-2026-81578 (CVSS 8.8) to the KEV this Monday; federal agencies have until September 14 to apply the second PaperCut patch under BOD 26-04.

On Monday, August 31, CISA added two vulnerabilities from PaperCut NG/MF to the Known Exploited Vulnerabilities catalog and activated Binding Operational Directive 26-04, which requires U.S. federal civilian agencies to implement mitigations by September 14. The vulnerabilities are CVE-2026-82078, an insecure reflection with CVSS 9.4, and CVE-2026-81578, an authentication issue for critical functions with CVSS 8.8. When chained together, they allow a remote and unauthenticated attacker to alter server settings and execute arbitrary Java bytecode within the context of the PaperCut process.


The sequence of events leading to CISA’s decision is short and dire. Attacks began on August 26. PaperCut issued a security bulletin on August 27 and released the first emergency patch the following day for versions 25 and 26 of NG/MF. Still on August 28, the vendor needed to publish a second emergency patch, now including version 24, after watchTowr researchers reproduced the pre-authentication chain and bypassed the initial patch in various ways. Huntress replicated the entire chain and observed exploitation in two client environments, with attackers in the reconnaissance phase.


Why the Second Emergency Patch Matters


Two patches in 48 hours for the same remote code execution chain indicate insufficient engineering in the first fix, shifting operational responsibility to the installed base. PaperCut is an Australian company based in Melbourne, with over 100 million users across educational, healthcare, and government environments in around 200 countries. The management server is exposed to the internet in a significant portion of these deployments, making the pre-authentication vector particularly dangerous.


The watchTowr team stated that the bypass route involved manipulation of access validation logic before the final authorization check, a pattern that has appeared in previous PaperCut incidents in 2023, when product vulnerabilities were exploited by Cl0p affiliates in environments with MOVEit. The repeated history supports CISA’s decision to enforce a mandatory patch.


How the Federal Order Propagates


BOD 26-04 applies to the U.S. Executive Branch civil sector, but the practical effect is broader. Managed vendors servicing the federal government also need to apply the patches in client environments to maintain contractual compliance, including integrators such as Leidos, CGI Federal, Peraki, and the U.S. operation of Capgemini Government Solutions. Major American universities, which represent a significant share of PaperCut's installed base, are likely to follow the same deadline by mirroring policy.


In the UK, the National Cyber Security Centre historically publishes alerts mirroring KEV entries with a lag of hours, which should prompt British universities, the NHS, and various councils to follow the same timeline until mid-September. In Germany, the BSI initiates its own Warn- und Informationsdienst with a similar procedure for federal ministries. For global companies with branches in the U.S., alignment is practically obligatory, as external auditors will mark the exception in any SOC 2 or ISO 27001 assessment submitted in October.


What the CISO Should Demand from the Vendor


The immediate operational point is to run the indicator checks published by Huntress and Rapid7, update to the patched versions of NG/MF, and, if the management server is exposed, take it offline until validated. The immediate contractual point differs: demand from PaperCut a public post-mortem on why the first fix failed and what changes in the testing process will prevent a third failure. If this response does not arrive before the next renewal cycle, the CISO gains ammunition to place the solution under vendor risk review. Repeating the purchase of the product without this formal requirement ignores that the line between an emergency patch and an emergency patch of an already issued emergency patch has been crossed twice in the same week.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk