PaperCut NG/MF contains a missing authentication for critical function vulnerability (CVE-2026-81578) that allows unauthenticated remote attackers to modify system configurations. The vulnerability can be chained with CVE-2026-82078 to potentially increase the impact of exploitation. CISA has flagged this vulnerability under BOD 26-04, requiring prioritized security updates. An urgent security advisory was published by PaperCut on August 27, 2026. The flaw is classified as high severity due to its unauthenticated remote exploitation potential. Organizations using PaperCut NG/MF are urged to apply patches immediately. CISA also provides forensic triage requirements as part of the BOD 26-04 implementation guidance.