PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
Updated: 05.09.2026 10:31
· First: 05.09.2026 10:31
· 📰 1 src / 1 articles
· H score: 41
Threat actors are actively exploiting PaperCut CVE-2026-81578 and CVE-2026-82078, putting schools and universities in the U.S. and Europe at risk of credential theft and follow-on compromise. Arctic Wolf observed the chain being used for command execution, reconnaissance, and privileged account creation on vulnerable servers. Post-exploitation activity also included registry hive collection tools, Meterpreter Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.