CVE-2026-81578 (CVSS 8.8) + CVE-2026-82078 (CVSS 9.4) can be chained from unauthenticated configuration manipulation to arbitrary Java code execution. The interesting part: the initial emergency patch was bypassed, leading to Emergency Patch Release 2. My technical breakdown covers the exploit chain, Udydn.class, Derby/JDBC activity, IOCs, Sigma/YARA detection, and incident-response steps.