The PaperCut vulnerabilities that CyberTech flagged in late August as under active attack with no patch available have now produced a specific victim pattern: attackers are chaining them into credential-theft campaigns against schools and universities across the United States and Europe. PaperCut disclosed the two flaws, an authentication bypass tracked as CVE-2026-81578 (CVSS 8.8) and a dynamic class-loading remote code execution bug tracked as CVE-2026-82078 (CVSS 9.4), on August 27. Chained together, they give an unauthenticated attacker a full path to code execution on a standard PaperCut NG or MF server. Both were added to CISA’s Known Exploited Vulnerabilities catalog on August 31.
Print management software is not a typical high-value target, which is exactly why it works as an entry point into education networks running lean IT teams. Once inside, the observed activity has focused on harvesting credentials and creating privileged accounts rather than immediate disruption, including registry-collection tooling aimed at reconstructing system-level secrets and reconnaissance commands to map hosts, users, and configuration. That pattern points to access brokering rather than a single smash-and-grab: stolen credentials from a print server can open a path into the identity systems that actually matter, including the student information and financial systems K-12 and university networks tend to share across departments.
The original insight for security leaders is about patch timing versus attacker timing. PaperCut shipped an emergency Release 3 patch on September 1 that added hardening against exactly this kind of chained exploitation, five days after the initial disclosure. Attackers did not wait for a lull between disclosure and patch adoption; they treated the disclosure itself as the starting gun. Any organization still running an unpatched PaperCut NG or MF instance should assume the exposure window has already been used, not merely theorized about.
Related on CyberTech: our original coverage of PaperCut’s initial warning before a patch existed, and a broader look at why a patch existing is not the same as a patch being applied.
Source: PaperCut Software