Ethical Hacking News
Attackers are exploiting newly disclosed PaperCut vulnerabilities to steal credentials from schools and universities in the U.S. and Europe. The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have been used to conduct command execution and reconnaissance, as well as create privileged accounts. Experts warn that stolen logins could give attackers a pathway into other critical systems, highlighting the need for immediate action to secure PaperCut installations.
vulnerabilities in PaperCut software have been exploited by attackers to steal credentials from vulnerable institutions. The identified vulnerabilities are an authentication bypass and remote code execution chain. Attackers have targeted PaperCut servers across the education sector, impacting organizations in the U.S. and Europe. Stolen logins could give attackers a pathway into other critical systems across the environment. Steps to secure PaperCut installations include restricting access to the internet, implementing regular security updates and patches, and monitoring for suspicious activity.
The recent discovery of vulnerabilities in PaperCut, a popular software used by schools and universities for managing print and copying resources, has left security experts and administrators on high alert. According to a report by Arctic Wolf, a cybersecurity company that observed the exploitation of these vulnerabilities, attackers have been using the newly disclosed PaperCut flaws to steal credentials from vulnerable institutions in the U.S. and Europe.
The identified vulnerabilities, CVE-2026-81578 and CVE-2026-82078, are an authentication bypass and remote code execution chain, respectively. These vulnerabilities have been exploited by attackers to conduct command execution and reconnaissance, as well as create privileged accounts. The Arctic Wolf Adversary Research Team observed post-exploitation activity that included the delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data.
The attackers have targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe. Some of the identified malicious activity includes running discovery commands like uname, whoami, ver, and tasklist, and privileged account creation ("Administrator17"). Inbound GET requests from "45.142.193[.]132" that request for "/custom/pcp_*.txt" and "/custom/web/pcp_*.txt" files on compromised hosts, containing harvested system and user data, have also been detected.
Furthermore, attackers have delivered credential-harvesting tools like lsa_collect.exe, lsa_collect_small.exe, and save_hives.exe via "certutil.exe" from "45.142.193[.]132". Retrieve Meterpreter Java payloads from, and establish sessions to, "194.180.48[.]134". The attackers have also used "findstr" to search PaperCut *.config files for the terms "password," "secret," "ldap," "bind,v and "token".
Arctic Wolf has warned that the stolen logins could give attackers a pathway into other critical systems across the environment. The cybersecurity company has advised users to restrict PaperCut servers from being exposed to the internet and monitor for the execution of cmd.exe, powershell.exe, or other scripting and command interpreters, along with commands containing whoami, tasklist, ver, or uname -a with pc-app.exe as the parent process.
In light of this vulnerability, it is essential for schools and universities to take immediate action to secure their PaperCut installations. This includes restricting access to the internet, implementing regular security updates and patches, and monitoring for suspicious activity. By taking these measures, institutions can help prevent further exploitation of this vulnerability and protect their sensitive data.
Related Information:
https://www.ethicalhackingnews.com/articles/Exploitation-of-PaperCut-Vulnerabilities-A-Threat-to-Education-Sector-Cybersecurity-ehn.shtml
https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
https://nvd.nist.gov/vuln/detail/CVE-2026-81578
https://www.cvedetails.com/cve/CVE-2026-81578/
https://nvd.nist.gov/vuln/detail/CVE-2026-82078
https://www.cvedetails.com/cve/CVE-2026-82078/
Published: Sat Sep 5 03:18:14 2026 by llama3.2 3B Q4_K_M