Overview
- PaperCut disclosed on Thursday, Aug. 27, that it had confirmed customer incidents and released emergency patches, then issued a second hardened update after researchers found patch bypasses.
- Two zero-days — CVE-2026-81578, an authentication bypass, and CVE-2026-82078, unsafe dynamic class loading in database utilities — can be chained to run arbitrary Java bytecode as the PaperCut process.
- Researchers reproduced the full exploit chain and published indicators of compromise that include malicious .class files placed in the install directory and Derby logs referencing memory:pwn.
- Telemetry shows a large attack surface with roughly 47% of tracked installs on older, unpatched versions and about 1,000 internet-exposed instances, and responders warn organizations to remove public access and hunt for signs of compromise.
- Recent vendor updates say attackers have used the access to run discovery commands and silently install remote-access tools such as SimpleHelp and AnyDesk, which raises risk of lateral moves into hospitals, schools and offices.