Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Reported exploitedPaperCut Application ServerOur summary
Arctic Wolf has confirmed active exploitation of CVE-2026-81578 and CVE-2026-82078, a combined authentication bypass and remote code execution vulnerability affecting PaperCut Application Server. Threat actors are leveraging this chain against K-12 schools and universities across the U.S. and Europe to perform system reconnaissance and establish persistent privileged access. Post-compromise activity includes the deployment of credential harvesting tools such as lsa_collect.exe and save_hives.exe, alongside Metasploit payloads intended to extract sensitive configuration data and SAM database access.
To mitigate these risks, administrators should immediately restrict direct internet exposure of PaperCut servers and monitor for anomalous command executions involving cmd.exe or PowerShell processes with pc-app.exe as the parent.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.