TTO-2026-0901-002 · September 1, 2026 Active ExploitationData Theft

PaperCut Zero-Day Exploitation Confirms Data Theft — Attackers Dumping Database Tables via Derby

papercut.comCVE-2026-81578CVE-2026-82078Auth bypass to user-lookup hijackDerby database table dumpDefused honeypots confirmed Aug 29Different from public RCE path100 million users 70,000 organizationsAttacker unidentified

Summary

Threat intelligence company Defused confirmed on September 1, 2026 that attackers exploiting the two PaperCut NG and MF zero-day vulnerabilities are pursuing a data theft objective distinct from the remote code execution path described in public technical writeups. Defused honeypots observed exploitation activity beginning August 29 UTC in which an attacker used the authentication bypass in CVE-2026-81578 not to achieve code execution but to hijack PaperCut's external user-lookup functionality and dump database tables via Derby, the embedded Java database engine used by PaperCut. The distinction is operationally significant: organizations that focused defensive monitoring on the RCE path may have missed the data theft variant. PaperCut confirmed in its advisory that the software serves 100 million users across more than 70,000 organizations including enterprises, state agencies, and educational institutions. No secondary malware, additional command-and-control traffic, or post-exploitation persistence has been observed beyond the database dump activity. The attacker responsible has not been identified and PaperCut has not attributed the attacks to any known threat actor. Both emergency patches — Release 1 and Release 2 — remain available. Organizations that have not applied Release 2 should do so immediately, as it includes additional hardening beyond the original patch.

Timeline

DateEvent
Aug 27, 2026PaperCut publishes emergency security advisory — active zero-day exploitation confirmed
Aug 28, 2026PaperCut Release 1 emergency patch published for v25 and v26
Aug 28, 2026PaperCut Release 2 emergency patch published with additional hardening including v24
Aug 29, 2026 UTCDefused honeypots detect exploitation activity — auth bypass used to hijack external user-lookup and dump Derby database tables
Sep 1, 2026Defused publishes confirmation of data theft exploitation path — distinct from public RCE writeups
Sep 1, 2026Attacker unidentified — no malware, C2 traffic, or persistence observed beyond database dump activity

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
papercut.com61.56✓✓✓Live
WarmBadge Intelligence Snapshot · Captured: September 1, 2026 UTC

Context

papercut.com scores 61.56 — a low-trust range score for a print management platform that has now been the subject of three separate The Trust Observatory bulletins in 2026 and has appeared in CISA's KEV catalog three times. The data theft exploitation path documented by Defused raises a specific defensive challenge: organizations that configured monitoring around the RCE indicators of compromise published by PaperCut and Huntress may not have been watching for the user-lookup hijack and Derby table dump pattern. Those are different log artifacts, different network signatures, and a different post-exploitation objective. An organization that applied the patch immediately after Release 2 and reviewed its logs against the RCE IOCs may still have an undetected data theft incident from the August 29 window if the Derby dump path was active before patching was complete.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 1, 2026