PaperCut Vulnerabilities Exploited in Education Sector Attacks

PaperCut Vulnerabilities Exploited in Education Sector Attacks

First seen 5 Sep 2026, 19:48 UTC ThehackernewsSecurityaffairs.Cogithub.com 72.6

Article Content

Browse articles
ThreatCluster

Attackers are exploiting two newly disclosed vulnerabilities in PaperCut, CVE-2026-81578 and CVE-2026-82078, to steal credentials from educational institutions in the U.S. and Europe. The Arctic Wolf Adversary Research Team reported that the flaws allow for an authentication bypass and remote code execution, leading to command execution and reconnaissance activities. The exploitation has impacted various organizations, including K-12 schools and universities. Attackers have been observed creating privileged accounts, such as 'Administrator17', and deploying credential-harvesting tools like lsa_collect.exe. The vulnerabilities were published on August 28, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on August 31, 2026. Security professionals are advised to restrict PaperCut servers from internet exposure and monitor for specific indicators of compromise.

Key Points: • Two critical PaperCut vulnerabilities (CVE-2026-81578, CVE-2026-82078) are actively exploited. • Attackers target educational institutions in the U.S. and Europe, creating privileged accounts. • Defenders should monitor for specific IOCs and restrict PaperCut server access.

Ask AI about this cluster

Timeline

2026-08-27
Active exploitation reported
PaperCut disclosed that the vulnerabilities were being actively exploited, leading to credential theft.
Securityaffairs.Co
2026-08-28
CVE-2026-81578 and CVE-2026-82078 published
PaperCut disclosed two vulnerabilities allowing authentication bypass and remote code execution.
Securityaffairs.Co
2026-08-31
CVE added to CISA KEV catalog
CISA confirmed active exploitation of the PaperCut vulnerabilities in the wild.
Securityaffairs.Co