Summary
Threat intelligence company Defused confirmed on September 1, 2026 that attackers exploiting the two PaperCut NG and MF zero-day vulnerabilities are pursuing a data theft objective distinct from the remote code execution path described in public technical writeups. Defused honeypots observed exploitation activity beginning August 29 UTC in which an attacker used the authentication bypass in CVE-2026-81578 not to achieve code execution but to hijack PaperCut's external user-lookup functionality and dump database tables via Derby, the embedded Java database engine used by PaperCut. The distinction is operationally significant: organizations that focused defensive monitoring on the RCE path may have missed the data theft variant. PaperCut confirmed in its advisory that the software serves 100 million users across more than 70,000 organizations including enterprises, state agencies, and educational institutions. No secondary malware, additional command-and-control traffic, or post-exploitation persistence has been observed beyond the database dump activity. The attacker responsible has not been identified and PaperCut has not attributed the attacks to any known threat actor. Both emergency patches — Release 1 and Release 2 — remain available. Organizations that have not applied Release 2 should do so immediately, as it includes additional hardening beyond the original patch.
Timeline
| Date | Event |
|---|---|
| Aug 27, 2026 | PaperCut publishes emergency security advisory — active zero-day exploitation confirmed |
| Aug 28, 2026 | PaperCut Release 1 emergency patch published for v25 and v26 |
| Aug 28, 2026 | PaperCut Release 2 emergency patch published with additional hardening including v24 |
| Aug 29, 2026 UTC | Defused honeypots detect exploitation activity — auth bypass used to hijack external user-lookup and dump Derby database tables |
| Sep 1, 2026 | Defused publishes confirmation of data theft exploitation path — distinct from public RCE writeups |
| Sep 1, 2026 | Attacker unidentified — no malware, C2 traffic, or persistence observed beyond database dump activity |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| papercut.com | 61.56 | ✓ | ✓ | ✓ | Live |
Context
papercut.com scores 61.56 — a low-trust range score for a print management platform that has now been the subject of three separate The Trust Observatory bulletins in 2026 and has appeared in CISA's KEV catalog three times. The data theft exploitation path documented by Defused raises a specific defensive challenge: organizations that configured monitoring around the RCE indicators of compromise published by PaperCut and Huntress may not have been watching for the user-lookup hijack and Derby table dump pattern. Those are different log artifacts, different network signatures, and a different post-exploitation objective. An organization that applied the patch immediately after Release 2 and reviewed its logs against the RCE IOCs may still have an undetected data theft incident from the August 29 window if the Derby dump path was active before patching was complete.
The Trust Observatory · thetrustobservatory.com · September 1, 2026