Particle.news

PaperCut Issues Hardened Patches as Zero-Days Are Actively Exploited

Unauthenticated flaws let attackers bypass permissions to load malicious Java classes, enabling remote code execution on exposed PaperCut servers.

Overview

  • PaperCut disclosed on Thursday, Aug. 27, that it had confirmed customer incidents and released emergency patches, then issued a second hardened update after researchers found patch bypasses.
  • Two zero-days — CVE-2026-81578, an authentication bypass, and CVE-2026-82078, unsafe dynamic class loading in database utilities — can be chained to run arbitrary Java bytecode as the PaperCut process.
  • Researchers reproduced the full exploit chain and published indicators of compromise that include malicious .class files placed in the install directory and Derby logs referencing memory:pwn.
  • Telemetry shows a large attack surface with roughly 47% of tracked installs on older, unpatched versions and about 1,000 internet-exposed instances, and responders warn organizations to remove public access and hunt for signs of compromise.
  • Recent vendor updates say attackers have used the access to run discovery commands and silently install remote-access tools such as SimpleHelp and AnyDesk, which raises risk of lateral moves into hospitals, schools and offices.