Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-06 ยท updated: 2026-09-06 ยท tags: [incident, cve, credential-theft, education] ยท confidence: high ยท affected_sectors: [education, technology] ยท au_impact: true

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Summary

Security researchers at Arctic Wolf observed threat actors chaining two newly disclosed flaws in PaperCut print-management software โ€” CVE-2026-81578 (an authentication bypass) and CVE-2026-82078 (a remote-code-execution issue) โ€” to attack schools and universities in the United States and Europe, conducting reconnaissance and executing commands to steal credentials.

Key Facts

  • Chain: Authentication bypass chained with remote code execution to gain a foothold.
  • Targets: Education institutions in the US and Europe.
  • KEV status: Both flaws were added to CISA's Known Exploited Vulnerabilities catalogue on 31 August 2026.
  • Vector context: Education is a frequent target owing to widespread PaperCut deployment across many devices and slower patching cadences.

Significance

PaperCut is an Australian vendor whose print-management software is ubiquitous in Australian schools, TAFEs and universities, making the education-sector credential-theft targeting directly relevant to Australian operators, who should confirm patched versions and monitor print-management authentication for unusual activity. This is the second PaperCut exploitation wave in a week.

Source