Hackers Exploit PaperCut Bugs to Steal Logins From Schools and Universities

Researchers say attackers are chaining two fresh flaws in the popular print management software to break into education networks across the US and Europe.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial shot of a dimly lit server rack in a data center, amber status LEDs glowing on a network security appliance, subtle warning light refle
Share

Key points

  • Attackers are actively exploiting two new flaws in PaperCut, the print management software used across thousands of schools, to steal login credentials.
  • The chain combines CVE-2026-81578, an authentication bypass, with CVE-2026-82078, a remote code execution flaw.
  • Arctic Wolf's Adversary Research Team says victims so far are concentrated in the education sector in the United States and Europe.
  • Attackers are running commands on servers, poking around internal networks, and lifting credentials for later use.
  • Schools running PaperCut should patch immediately and treat any exposed server as potentially breached.

Schools and universities are being broken into through their print servers.

Researchers at Arctic Wolf say attackers are exploiting two freshly disclosed bugs in PaperCut, a widely used piece of software that manages printing on school and office networks, to steal usernames and passwords from education institutions across the United States and Europe.

The attack was first reported by The Hacker News.

What are the flaws?

The hackers are chaining two vulnerabilities together to take control of PaperCut servers.

The first, CVE-2026-81578, is an authentication bypass. In plain terms, it lets an attacker skip the login screen entirely and act as if they were already signed in as an administrator.

The second, CVE-2026-82078, is a remote code execution bug. That means once the attacker is past the login, they can make the server run any command they choose, as if they were sitting at the keyboard.

Used together, the two turn an internet-facing print server into a foothold inside the school's network.

Detail What we know
Software affected PaperCut print management server
Vulnerabilities CVE-2026-81578, CVE-2026-82078
Attack type Auth bypass chained with remote code execution
Victims observed Education sector, US and Europe
Attacker goal Command execution, reconnaissance, credential theft

What are the attackers doing once they get in?

Once inside, the intruders are running commands on the server, mapping out the wider network, and stealing credentials they can reuse elsewhere.

Arctic Wolf's Adversary Research Team describes the activity as reconnaissance followed by credential theft, the classic early stages of a bigger intrusion. Stolen passwords from a print server often unlock email accounts, file shares, and student information systems, because staff tend to reuse the same login across systems.

That matters. A PaperCut server rarely holds sensitive data itself. But it usually sits on the same internal network as the payroll system, the student database, and the finance team's shared drive.

Why target schools?

Because they are soft, connected, and hold a lot of personal data.

Education networks tend to run older software, have small IT teams, and expose services to the public internet so staff and students can print from home. PaperCut fits all three boxes. Ransomware crews have leaned on the same product before: a set of PaperCut flaws in 2023 was exploited at scale by groups including Cl0p and LockBit.

US schools fall under a patchwork of state breach-notification laws and, where student data is involved, the Family Educational Rights and Privacy Act. In the UK and EU, the Information Commissioner's Office and equivalent data protection authorities have jurisdiction under the UK GDPR and GDPR, with a 72-hour breach notification clock.

What should schools and staff do now?

If your organisation runs PaperCut, patch to the latest version today and check whether the admin interface has been reachable from the public internet. Assume any exposed server may already have been touched.

Staff and students at affected institutions should watch for password reset emails they did not request, unusual login alerts, and phishing messages that reference real internal systems. Change any password reused between a school account and a personal one. Turn on multi-factor authentication where the option exists.

IT teams should hunt for unexpected commands run by the PaperCut service account, new local users, and outbound connections from the print server to unfamiliar addresses.

© 2026 Threat Vectr