< Back to all clusters
[TECHNOLOGY] · United States, Germany · 5 sources

started · updated

PaperCut vulnerabilities exploited to target schools and universities

Cyberattackers are exploiting newly disclosed vulnerabilities in PaperCut software to steal credentials from educational institutions in the United States and Europe. The attacks target a range of organizations, from K-12 schools to major universities.

According to the Arctic Wolf Adversary Research Team, attackers are utilizing a chain of vulnerabilities, specifically CVE-2026-81578 and CVE-2026-82078, to achieve authentication bypass and remote code execution. Once access is gained, the actors perform reconnaissance, execute commands, and create privileged accounts to expand their reach.

Post-exploitation activities include the use of tools to collect Windows registry hives and the deployment of Metasploit/Meterpreter-related Java payloads. Security researchers noted that attackers have used commands to identify hosts, users, and sensitive configuration data, specifically searching for terms like ‘password’, ‘secret’, and ‘token’ within PaperCut configuration files. Experts recommend that organizations avoid exposing PaperCut servers directly to the internet and monitor for unusual command-interpreter activity.

Entities

Arctic Wolf · PaperCut