CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with two new vulnerabilities.
Intelligence analysis by Qwen 2.5 (3B)
CISA has added two vulnerabilities to its KEV Catalog based on evidence of active exploitation, including a PaperCut NG/MF authentication issue and an unsafe reflection vulnerability.
CISA found two new problems in computer systems that could let bad guys do bad things. They added these problems to a list so people can be extra careful and fix them quickly.
Analysis
{"heading":"KEV Nomination Form","subheading":"Submitting Exploited Vulnerabilities","paragraph_1":"CISA encourages organizations to submit potential KEV additions through its KEV Nomination Form, which must include a CVE ID, evidence of exploitation, and clear mitigation guidance.","paragraph_2":"CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.","paragraph_3":"CISA will also consider potential KEV additions submitted through the nomination form."}
Key points
- CISA added two new vulnerabilities to its KEV Catalog
- CVE-2026-81578 and CVE-2026-82078 are the two vulnerabilities
- BOD 26-04 requires federal agencies to prioritize the remediation of high-risk vulnerabilities
- CISA encourages all organizations to adopt risk-based vulnerability management
- CISA will continue to add vulnerabilities to the catalog that meet the specified criteria
By adding these vulnerabilities to the catalog, CISA hopes to help federal agencies stay safer and more secure.
If these vulnerabilities are not fixed quickly, they could let bad guys do even more damage to federal systems.


