Security

Attackers Exploit Chained PaperCut Zero-Days to Install Remote Access Tools

Hackers are breaking into exposed PaperCut print servers by chaining two unpatched flaws, then quietly installing SimpleHelp and AnyDesk for lasting access. CISA has added both vulnerabilities to its catalog of actively exploited bugs as emergency fixes roll out.

T
By TechQuire Daily Staff TechQuire Daily Staff
August 31, 2026 / 6 min read

Print management software is not the kind of technology that usually makes headlines, which is precisely why attackers keep choosing it as a door into corporate networks. PaperCut NG and PaperCut MF, the print management platforms used by thousands of schools, universities and enterprises to control who prints what and at what cost, have become the target of an active exploitation campaign that began in late August and is still unfolding. On Aug 31, the U.S. Cybersecurity and Infrastructure Security Agency added the two underlying vulnerabilities to its Known Exploited Vulnerabilities catalog, the federal government's list of flaws that are demonstrably being used in real attacks, and security firms reported that attackers who break in are quietly installing remote access software so they can return at will.

The campaign is a reminder that the weakest point in most organizations is not the crown-jewel database or the AI system, but the boring, internet-exposed server that nobody thinks about, in this case the box that tells the office printer how to work. When it falls, it often brings the rest of the network with it.

Key Facts

Help Net Security reported on Aug 31 that the threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, according to PaperCut Software's most recent update on the campaign. PaperCut first warned of in-the-wild compromises on Aug 27, urging customers to immediately restrict web access to the Application Server to trusted IP addresses, and its investigation identified two chained zero-days: CVE-2026-81578, an improper access control vulnerability in the web management interface rated 8.8 on the CVSS scale, and CVE-2026-82078, an unsafe dynamic class loading flaw in the database connection utilities. Rapid7 reported on Aug 28 that the two flaws, chained together, let an unauthenticated remote attacker bypass authentication, modify system configurations and execute arbitrary Java bytecode in the security context of the PaperCut server process.

PaperCut released emergency patches on Aug 28, publishing a second round the same day after researchers at Huntress and watchTowr found ways around the first fix. BleepingComputer reported on Aug 28 that the second release, Emergency Patch Release 2, extends coverage to version 24 of the software, after the initial patches covered only versions 25 and 26. The scope of the exposure is significant. Huntress, which tracks the software across its customer base, found evidence of exploitation in two customer environments and noted that 47% of the approximately 2,500 PaperCut installations it monitors are running version 23 or older, versions for which no patch is currently available.

The post-exploitation behavior is what makes the campaign distinctive. According to the indicators of compromise published by PaperCut and reported by Help Net Security, after gaining access the attackers list users and privileges, enumerate domain controllers, and download a payload from a file-sharing host that silently installs SimpleHelp, a legitimate remote access tool, configured to run as a service and auto-start, followed by a second download of AnyDesk to establish a redundant remote access channel. The use of legitimate software, rather than custom malware, makes the intrusion harder to detect, since remote access tools are common in IT environments and antivirus products generally trust them.

Analysis

The bigger picture here is that this campaign is the modern pattern for network intrusion: exploit a forgotten, internet-facing appliance, install dual remote access tools for persistence, and only then decide what to steal. What this really means is that the attackers are not breaking in to print more paper; they are buying a durable foothold that they can monetize later, through ransomware, credential theft or espionage, and the choice of SimpleHelp plus AnyDesk is a deliberate resilience play, because removing one tool does not remove the attacker's access. The 2023 precedent makes the stakes clear. That year, attackers exploited CVE-2023-27350, an earlier PaperCut flaw, at scale, and it was ultimately linked to ransomware operations including Clop, LockBit and the Bl00dy Ransomware Gang, meaning the print server has a documented history of being a gateway to extortion.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on Aug 31, according to Help Net Security's Aug 31 report on the campaign.

The most troubling data point in the incident is the patching gap. Huntress's finding that 47% of tracked installations are on version 23 or older, with no patch available, means a large share of the affected installed base cannot simply update and be safe. Those organizations are left with mitigation only: blocking internet access to the Application Server, hunting for the remote access tools, and hoping the attackers have not already established persistence. This is the recurring tragedy of appliance software, where the organizations most likely to be targeted, underfunded school districts and small businesses that run print servers because they are cheap, are also the least likely to have the IT staff to keep versions current.

There is also a coordination angle worth noting. The disclosure timeline, with PaperCut warning on Aug 27, patches on Aug 28, CISA adding the CVEs to KEV on Aug 31 and a Metasploit module becoming available the same day, shows how fast the exploitation window moves. The moment a Metasploit module is public, attackers who cannot write their own exploits gain a free, reliable tool, which is why the CISA KEV listing and the emergency patch cadence matter so much. The gap between the first patch and universal deployment will be measured in days, and every day of exposure is another chance for a foothold.

Why It Matters

For the thousands of organizations running PaperCut, the message is immediate and practical: if the Application Server is reachable from the internet, restrict it now, apply Emergency Patch Release 2, and check for signs of SimpleHelp, AnyDesk or the indicators PaperCut has published. For the broader security community, the campaign is a case study in how attackers combine a chained zero-day with legitimate remote access tools to build persistence that evades detection. For CISOs, it is a reminder that the internet-exposed appliance, the print server, the VPN gateway, the fax-to-email box, is where breaches begin, and that the software with the least security investment is often the one that lets an intruder into the network.

PaperCut warned customers on Aug 27 to restrict web access to the Application Server to trusted IP addresses.

The education angle makes the campaign especially consequential. PaperCut is ubiquitous in schools and universities, where print management is a budget necessity and where IT staffing is often thin, and it was a university customer's security team that helped PaperCut reproduce the vulnerabilities. A successful intrusion into a school district's print server is rarely the end of the story, because the same network segment that runs print services often hosts student records, payroll and other sensitive data, and the attackers who install SimpleHelp and AnyDesk are not installing them for fun. The 2023 precedent showed that PaperCut access became a vector for ransomware gangs, and the education sector is a favorite target for those gangs precisely because the data is sensitive and the defenses are weak.

Next Up

In the coming days, expect PaperCut to continue updating its indicators of compromise as incident-response firms share more detail, and watch for whether the attackers expand their targeting beyond the initial wave or begin converting footholds into ransomware, which would echo the 2023 playbook. Also monitor whether CISA's KEV listing prompts a surge of patching among federal contractors, which has been the pattern for past KEV additions, and whether the security community identifies the specific threat actor behind the campaign. The longer-term question is whether PaperCut and similar appliance vendors can push their aging installed base onto supported versions before the next zero-day arrives, because the 47% patching gap suggests the industry's weakest customers are also its most exposed.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.