CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5737

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are actively exploiting two recently disclosed PaperCut vulnerabilities, an authentication bypass (CVE-2026-81578) and remote code execution (RCE) flaw (CVE-2026-82078), to target schools and universities in the U.S. and Europe. Arctic Wolf's Adversary Research Team observed attackers using the vulnerability chain to execute commands, conduct reconnaissance, and steal credentials from educational institutions.

Why it matters: Schools and universities using PaperCut should immediately patch CVE-2026-81578 and CVE-2026-82078 to prevent attackers from gaining RCE and harvesting user credentials; this is an active in-the-wild exploitation targeting your sector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are actively exploiting two recently disclosed PaperCut vulnerabilities, an authentication bypass (CVE-2026-81578) and remote code execution (RCE) flaw (CVE-2026-82078), to target schools and universities in the U.S. and Europe. Arctic Wolf's Adversary Research Team observed attackers using the vulnerability chain to execute commands, conduct reconnaissance, and steal credentials from educational institutions.

Why it matters: Schools and universities using PaperCut should immediately patch CVE-2026-81578 and CVE-2026-82078 to prevent attackers from gaining RCE and harvesting user credentials; this is an active in-the-wild exploitation targeting your sector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary