← Field Journal

Cyber ·

CISA Adds Two New Vulnerabilities to Known Exploited Vulnerabilities Catalog

CISA's latest vulnerabilities highlight significant x-risk in federal cybersecurity efforts.

CISA has recently added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation and emphasizing the urgency of cybersecurity measures.

What the Signal Actually Is

On August 31, 2026, CISA announced the inclusion of two vulnerabilities related to PaperCut NG/MF: CVE-2026-81578, which involves missing authentication for critical functions, and CVE-2026-82078, characterized as an unsafe reflection vulnerability. These vulnerabilities are noted as frequent attack vectors for malicious cyber actors and pose significant risks to federal enterprises. The Binding Operational Directive (BOD) 26-04 mandates that Federal Civilian Executive Branch (FCEB) agencies prioritize the remediation of high-risk vulnerabilities listed in the KEV Catalog, particularly those that can grant total control of an asset post-exploitation.

Why It Matters for Human Extinction Risk

The cybersecurity landscape is increasingly critical for assessing existential risks. Cyber vulnerabilities can lead to significant disruptions in essential services, including those related to national security, public health, and critical infrastructure. The exploitation of vulnerabilities like those added to the KEV Catalog could lead to unauthorized access to sensitive systems, potentially enabling malicious actors to disrupt societal functions or manipulate critical data. As CISA encourages all organizations to adopt risk-based vulnerability management, the implications of these vulnerabilities extend beyond federal agencies, impacting private sectors and global cybersecurity frameworks. The interconnected nature of our digital infrastructure means that a successful exploit could have cascading effects, heightening existential risks.

Our Take

While the addition of these vulnerabilities to the KEV Catalog is concerning, it is also a reminder of the importance of proactive cybersecurity measures. The systematic approach outlined in BOD 26-04 to prioritize remediation based on risk is a step in the right direction, but the effectiveness of these measures relies on swift action from all organizations, not just federal agencies. The fact that CISA is actively updating the KEV Catalog indicates a responsive strategy to emerging threats, yet the ongoing prevalence of exploitable vulnerabilities underscores a persistent risk environment. It is crucial for organizations to remain vigilant and prioritize the mitigation of known vulnerabilities to reduce the likelihood of exploitation that could escalate into larger crises.

*Source: CISA