← Back to Tech & Science

Threat Actors Exploit PaperCut Flaws to Steal Education Credentials

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WASHINGTON — Cybercriminals have successfully exploited critical vulnerabilities in PaperCut software to steal credentials from educational institutions across the United States and Europe, marking a significant escalation in attacks targeting the education sector. The Arctic Wolf Adversary Research Team identified the campaign on Sept. 5, 2026, detailing how threat actors leveraged two newly disclosed flaws to gain unauthorized access to critical systems.

The attack campaign targets PaperCut NG/MF, a widely deployed print management solution used by universities and schools to control printing, scanning, and user authentication. The attackers utilized two specific vulnerabilities, designated CVE-2026-81578 and CVE-2026-82078, to execute remote code execution and bypass security controls. By compromising these servers, adversaries were able to harvest login credentials, allowing them to move laterally within institutional networks and access sensitive data repositories.

The scope of the intrusion spans dozens of higher education facilities in North America and Western Europe. In several confirmed cases, attackers gained entry to administrative portals where student records, financial aid information, and faculty research data are stored. The compromised credentials were subsequently used to authenticate into other internal systems, expanding the attackers' foothold beyond the initial print management infrastructure.

PaperCut MF has acknowledged the existence of the vulnerabilities and released patches to address the flaws. However, security researchers warn that a significant number of institutions may still be running unpatched versions of the software, leaving them exposed to further exploitation. The speed at which threat actors deployed these exploits suggests they were aware of the vulnerabilities before public disclosure or moved rapidly once details emerged.

The Arctic Wolf Adversary Research Team noted that the primary objective of the campaign appears to be credential theft rather than immediate ransomware deployment. By securing valid user accounts, attackers can maintain persistent access to networks while evading detection mechanisms designed to flag malicious software. This method allows them to operate within the trusted perimeter of the institutions they target.

Educational administrators are urged to immediately verify their PaperCut installations and apply the latest security updates. Institutions are also advised to audit recent login activity for anomalies that could indicate compromised credentials. Despite the urgency, questions remain regarding the full extent of the data exfiltration and whether the stolen credentials have been sold on dark web marketplaces.

As investigations continue, cybersecurity firms are monitoring for signs of similar attacks targeting other sectors that rely on PaperCut software. The incident highlights the growing risk posed to the education sector as attackers increasingly focus on supply chain vulnerabilities to access high-value targets.

Discussion

0 / 2000