Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

Threat actors are actively exploiting PaperCut CVE-2026-81578 and CVE-2026-82078, putting schools and universities in the U.S. and Europe at risk of credential theft and follow-on compromise. Arctic Wolf observed the chain being used for command execution, reconnaissance, and privileged account creation on vulnerable servers. Post-exploitation activity also included registry hive collection tools, Meterpreter Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.

Related Happenings

PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)

Vulnerability
H score51 First: 28.08.2026 20:12 Last: 28.08.2026 20:12 Sources 1

About this happening: PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code executio...

PaperCut customer confirmed compromise incidents

Incident
H score41 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....

Latest development: 01.09.2026 10:48

Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release
H score51 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

About this happening: PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...

Latest development: 01.09.2026 10:48

Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.

Paperclip RCE and auth-bypass flaws multiple vulnerabilities security flaw (CVE-2026-41679)

Vulnerability
H score41 First: 05.08.2026 17:30 Last: 05.08.2026 17:30 Sources 1

About this happening: Paperclip's three vulnerabilities affected authenticated deployments and local development mode, enabling command execution on network servers and a deve...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

Timeline

  1. 05.09.2026 10:31 2 articles · 2h ago

    Active PaperCut exploitation targets schools and universities

    Exploitation Observed

    Arctic Wolf said attackers were actively exploiting CVE-2026-81578 and CVE-2026-82078 in vulnerable PaperCut servers used by K-12 schools and major universities in the U.S. and Europe, with post-exploitation activity including command execution, reconnaissance, privileged account creation, registry hive collection, Meterpreter-related Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.

    Show sources