CVE Tools

Attackers plant remote access tools on compromised PaperCut servers

Help Net SecurityBy Zeljka Zorz

Reported exploitedPaperCut NGPaperCut MF

Our summary

Threat actors are actively exploiting two zero-day vulnerabilities in PaperCut Application Servers to covertly install legitimate remote access software, specifically SimpleHelp and AnyDesk. The campaign leverages a chain of flaws, including CVE-2026-81578 (improper access control) and CVE-2026-82078 (unsafe dynamic class loading), which allow unauthenticated attackers to bypass security controls and execute arbitrary code. PaperCut Software has released emergency patches for v24, v25, and v26 branches, urging all customers to restrict web access to trusted IPs and investigate potential compromise via indicators such as unauthorized Windows services.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store