Exploited in the wild PaperCut NG rce PaperCut MF PaperCut auth-bypass
Attackers plant remote access tools on compromised PaperCut servers
CVE Tools coverage
Threat actors are actively exploiting two zero-day vulnerabilities in PaperCut Application Servers to covertly install legitimate remote access software, specifically SimpleHelp and AnyDesk. The campaign leverages a chain of flaws, including CVE-2026-81578 (improper access control) and CVE-2026-82078 (unsafe dynamic class loading), which allow unauthenticated attackers to bypass security controls and execute arbitrary code. PaperCut Software has released emergency patches for v24, v25, and v26 branches, urging all customers to restrict web access to trusted IPs and investigate potential compromise via indicators such as unauthorized Windows services.