CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

September 5, 2026

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities Ravie LakshmananSep 05, 2026Vulnerability / Web Security Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts. "Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf said. The cybersecurity company told The Hacker News that the activity has targeted vulnerable…

CVEs: CVE-2026-81578, CVE-2026-82078