PaperCut says a threat actor is exploiting two zero-day vulnerabilities in PaperCut NG and MF to gain access to internet-facing Application Servers and covertly install legitimate remote access tools such as SimpleHelp and AnyDesk. The vendor has released emergency patches and urged customers to restrict access, preserve forensic evidence, and rebuild affected servers if compromise is suspected. #PaperCut #CVE-2026-81578 #CVE-2026-82078 #SimpleHelp #AnyDesk
Keypoints
- Attackers are targeting internet-facing PaperCut Application Servers.
- Two zero-days, CVE-2026-81578 and CVE-2026-82078, enabled unauthenticated access and code execution.
- The post-compromise activity includes installing SimpleHelp and AnyDesk for remote access.
- PaperCut released emergency patches and advised restricting web access to trusted IP addresses.
- Customers should preserve evidence, review logs, and rebuild servers if compromise is suspected.
Read More: https://www.helpnetsecurity.com/2026/08/31/papercut-attack-remote-access-tools/