← Back to blog

PaperCut Vulnerabilities Exploited for Credential Theft in Education Sector

Attackers are leveraging critical PaperCut flaws to steal credentials from schools and universities across the U.S. and Europe. These exploits enable remote code execution and unauthorized access, posing a significant risk to educational institutions.

TL;DR

  • Threat actors are actively exploiting two PaperCut vulnerabilities: CVE-2026-81578 and CVE-2026-82078.
  • These flaws allow authentication bypass and remote code execution, leading to credential theft.
  • Educational institutions in the U.S. and Europe are the primary targets.
  • Arctic Wolf Adversary Research Team reported observing active exploitation in the wild.
  • Organizations using PaperCut should immediately apply available patches and monitor for suspicious activity.

Cybercriminals are increasingly targeting educational institutions by exploiting recently disclosed vulnerabilities in PaperCut software. These attacks leverage a combination of authentication bypass and remote code execution flaws to gain unauthorized access and steal sensitive credentials.

According to the Arctic Wolf Adversary Research Team, the exploited vulnerabilities—CVE-2026-81578 and CVE-2026-82078—have been used to perform reconnaissance and execute commands on compromised systems. The primary victims are schools and universities across the United States and Europe, highlighting the need for immediate patching and enhanced monitoring.

Vulnerability Details

  • CVE-2026-81578 is an authentication bypass vulnerability that allows attackers to circumvent login mechanisms.
  • CVE-2026-82078 enables remote code execution, giving attackers full control over affected systems.
  • Both vulnerabilities can be chained together to achieve deeper system compromise without prior authentication.
  • Exploitation leads to unauthorized access, data theft, and potential lateral movement within networks.

Impact and Recommendations

  • Educational institutions using PaperCut are at high risk due to widespread deployment in academic environments.
  • Attackers have used these flaws to conduct reconnaissance and establish persistent access.
  • Organizations should immediately apply vendor-released patches to mitigate these vulnerabilities.
  • Network defenders should monitor for unusual outbound traffic and unexpected process executions.
  • Implementing multi-factor authentication and network segmentation can reduce the impact of such compromises.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

PaperCut Vulnerabilities Exploited for Credential Theft in Education Sector — Agent Breach Blog | Agent Breach