PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Threat actors are actively exploiting PaperCut CVE-2026-81578 and CVE-2026-82078, putting schools and universities in the U.S. and Europe at risk of credential theft and follow-on compromise. Arctic Wolf observed the chain being used for command execution, reconnaissance, and privileged account creation on vulnerable servers. Post-exploitation activity also included registry hive collection tools, Meterpreter Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.
Related Happenings
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
H score51
First: 28.08.2026 20:12
Last: 28.08.2026 20:12
Sources 1
About this happening:
PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code executio...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: PaperCut NG and PaperCut MF are facing active exploitation of two newly patched flaws, allowing attackers to bypass authentication and reach remote code executio...
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentAbout this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
PaperCut emergency patches for public-facing NG/MF servers
Security Patch Release
H score51
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
PaperCut emergency patches for public-facing NG/MF servers
Security Patch ReleaseAbout this happening: PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the prin...
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.
Paperclip RCE and auth-bypass flaws multiple vulnerabilities security flaw (CVE-2026-41679)
Vulnerability
H score41
First: 05.08.2026 17:30
Last: 05.08.2026 17:30
Sources 1
About this happening:
Paperclip's three vulnerabilities affected authenticated deployments and local development mode, enabling command execution on network servers and a deve...
Paperclip RCE and auth-bypass flaws multiple vulnerabilities security flaw (CVE-2026-41679)
VulnerabilityAbout this happening: Paperclip's three vulnerabilities affected authenticated deployments and local development mode, enabling command execution on network servers and a deve...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
H score89
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
Timeline
-
05.09.2026 10:31 2 articles · 2h ago
Active PaperCut exploitation targets schools and universities
Exploitation ObservedArctic Wolf said attackers were actively exploiting CVE-2026-81578 and CVE-2026-82078 in vulnerable PaperCut servers used by K-12 schools and major universities in the U.S. and Europe, with post-exploitation activity including command execution, reconnaissance, privileged account creation, registry hive collection, Meterpreter-related Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.
Show sources
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — thehackernews.com — 05.09.2026 10:31
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — thehackernews.com — 05.09.2026 10:31