Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
- ID
- 21745
- Status
- summarized
- Published
- 05 Sep 2026, 3:31 PM
- Fetched
- 05 Sep 2026, 4:59 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 05 Sep 2026, 4:59 PM
- Tags
- Audience
- developers
What happened
Arctic Wolf reports attackers exploiting two newly disclosed PaperCut vulnerabilities (CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an RCE) to steal credentials from U.S. and European schools and universities. Post-exploitation includes deploying Meterpreter Java payloads, credential-harvesting tools like lsa_collect.exe, creating privileged accounts (e.g. 'Administrator17'), and searching PaperCut config files for passwords, secrets, LDAP bind credentials, and tokens.
Why it matters
If your organization runs PaperCut print management servers exposed to the internet, restrict that exposure immediately and monitor for cmd.exe/powershell.exe spawned by pc-app.exe with commands like whoami, tasklist, ver, or uname. For most builders not running PaperCut, there is no direct action item.
Discussion angle
A quick reminder segment: print management software is often internet-exposed and forgotten in patch cycles — worth checking whether any infrastructure your team touches has similar neglected admin panels.