RECENT attacks targeting U.S. and European schools are exploiting two newly disclosed vulnerabilities in PaperCut, identified as CVE-2026-81578 and CVE-2026-82078. Arctic Wolf researchers reported that attackers are using an authentication bypass in conjunction with remote code execution to gain unauthorized access and create privileged accounts. Exploits include running commands, conducting reconnaissance, and utilizing credential-harvesting tools.
PaperCut, an enterprise print-management solution, has a history of being exploited, including prior ransomware attacks. Security advisories recommend reviewing server logs for exploitation indicators, monitoring for suspicious activity, and applying security patches.