CVE-2026-81578 (CVSS 8.8) + CVE-2026-82078 (CVSS 9.4) can be chained from unauthenticated configuration manipulation to arbitrary Java code execution. The interesting part: the initial emergency patch was bypassed, leading to Emergency Patch Release 2. My technical breakdown covers the exploit chain, Udydn.class, Derby/JDBC activity, IOCs, Sigma/YARA detection, and incident-response steps.

  • solrize@lemmy.ml
    link
    fedilink
    English
    arrow-up
    6
    ·
    9 days ago

    From the linked post:

    It is tempting to file “print management software” under boring infrastructure, and that is precisely what makes this class of product so attractive to attackers. PaperCut NG and PaperCut MF are among the most widely deployed print-management platforms in the world, dominating large enterprises, healthcare networks, and higher education — sectors where on-premise print infrastructure remains the norm and where the Application Server is routinely joined to Active Directory, holds privileged service accounts, and sits on network segments rich with lateral-movement opportunities. On Windows, the Application Server binary pc-app.exe runs as a service with SYSTEM privileges by default, so any code execution inside the Java process is, for practical purposes, full host compromise.