Attackers plant remote access tools on compromised PaperCut servers
Reported exploitedPaperCut NGPaperCut MFOur summary
Threat actors are actively exploiting two zero-day vulnerabilities in PaperCut Application Servers to covertly install legitimate remote access software, specifically SimpleHelp and AnyDesk. The campaign leverages a chain of flaws, including CVE-2026-81578 (improper access control) and CVE-2026-82078 (unsafe dynamic class loading), which allow unauthenticated attackers to bypass security controls and execute arbitrary code. PaperCut Software has released emergency patches for v24, v25, and v26 branches, urging all customers to restrict web access to trusted IPs and investigate potential compromise via indicators such as unauthorized Windows services.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.