Executive Summary
In September 2026, threat actors actively exploited two chained PaperCut vulnerabilities (CVE-2026-81578 and CVE-2026-82078) to conduct widespread credential theft attacks against educational institutions across the United States and Europe. The attack chain leveraged an authentication bypass vulnerability followed by remote code execution to deploy registry harvesting tools, Metasploit payloads, and create privileged accounts on compromised print management servers. Arctic Wolf researchers observed attackers systematically extracting Windows registry hives, searching configuration files for sensitive credentials, and establishing persistent access through Meterpreter sessions, targeting organizations from K-12 schools to major universities.
This campaign highlights the continued targeting of educational infrastructure, which often lacks robust security controls and runs legacy systems with delayed patching cycles, making institutions particularly vulnerable to supply chain and third-party application exploits.
Why This Matters Now
Educational institutions face increasing cyber threats with limited security budgets, and this PaperCut exploit demonstrates how attackers systematically target sector-specific vulnerabilities to harvest credentials for broader network access and potential data theft.
Attack Path Analysis
Attackers exploited CVE-2026-81578 and CVE-2026-82078 in internet-exposed PaperCut servers to achieve authentication bypass and remote code execution, then escalated privileges by creating Administrator17 accounts and harvesting credentials via registry tools. They established command and control channels to Meterpreter infrastructure while exfiltrating sensitive configuration data and system credentials to compromise additional systems across educational networks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) on internet-exposed PaperCut servers to gain initial access
Related CVEs
CVE-2023-27350
CVSS 9.8Authentication bypass vulnerability in PaperCut MF/NG allows unauthenticated attackers to execute arbitrary code via crafted requests.
Affected Products:
PaperCut Software PaperCut MF – < 22.0.9
PaperCut Software PaperCut NG – < 22.0.9
Exploit Status:
exploited in the wildCVE-2023-27351
CVSS 7.5Improper access control in PaperCut MF/NG allows authenticated users to execute arbitrary code via path traversal.
Affected Products:
PaperCut Software PaperCut MF – < 22.0.9
PaperCut Software PaperCut NG – < 22.0.9
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter: Windows Command Shell
System Information Discovery
System Owner/User Discovery
OS Credential Dumping: Security Account Manager
Ingress Tool Transfer
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Process
Control ID: 6.2.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08(b)
CISA Zero Trust Maturity Model 2.0 – Asset Inventory and Network Architecture Documentation
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Major universities directly targeted in PaperCut exploitation campaigns enabling credential theft, privileged account creation, and potential lateral movement across campus networks.
Primary/Secondary Education
K-12 schools vulnerable to CVE-2026-81578/82078 exploitation allowing attackers to harvest credentials, deploy registry collection tools, and compromise student/administrative systems.
Information Technology/IT
IT service providers managing educational PaperCut deployments face credential harvesting attacks, Meterpreter payload delivery, and potential multi-client environment compromise through lateral movement.
Government Administration
Educational government agencies utilizing PaperCut systems exposed to authentication bypass attacks, SAM database access, and compliance violations under HIPAA/NIST frameworks.
Sources
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universitieshttps://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.htmlVerified
- PaperCut Security Bulletin - Critical Security Update Requiredhttps://www.papercut.com/kb/Main/Security-Bulletin-May-2023Verified
- CISA Known Exploited Vulnerabilities Catalog - PaperCuthttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Arctic Wolf Adversary Research - PaperCut CVE Exploitationhttps://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-papercut-cve-exploitationVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this PaperCut attack by limiting lateral movement paths and reducing blast radius across educational network segments. Segmented workload isolation and controlled egress policies could significantly reduce attacker reachability to critical systems.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise may still occur on exposed systems, but CNSF workload isolation would likely limit the attack scope to the compromised PaperCut server segment rather than providing broad network access across educational infrastructure.
Control: Zero Trust Segmentation
Mitigation: Privilege escalation activities may proceed on the compromised system, but zero trust segmentation would likely constrain the administrative reach to only the segmented workload rather than enabling domain-wide administrative access across educational systems.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely be significantly constrained as east-west traffic controls could block unauthorized access paths between educational network segments, limiting the attacker's ability to reach critical systems using harvested credentials.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications may be established, but multicloud visibility would likely detect and limit the scope of C2 traffic across the educational network, constraining the attacker's ability to orchestrate widespread operations.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration activities would likely be constrained through egress policy enforcement, potentially blocking or limiting unauthorized outbound data transfers to external command and control infrastructure from educational network segments.
While some credential compromise may occur within the affected segment, the overall impact to educational infrastructure would likely be significantly reduced due to network segmentation limiting the blast radius of the attack.
Impact at a Glance
Affected Business Functions
- Student Information Systems
- Print Management Services
- Network Authentication
- Administrative Operations
Estimated downtime: 7 days
Estimated loss: $150,000
Student and faculty credentials, LDAP authentication data, system configuration files containing passwords and tokens, Windows registry hives including SAM database with potential access to domain credentials across educational networks
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement from compromised PaperCut servers to critical educational systems
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to attacker infrastructure like 45.142.193.132 and 194.180.48.134
- • Enable Threat Detection & Anomaly Response to identify suspicious registry harvesting tools and Meterpreter payload execution
- • Establish East-West Traffic Security controls to monitor and restrict workload-to-workload communications within the campus network
- • Implement Multicloud Visibility & Control to detect anomalous automation patterns and repeated malformed requests targeting vulnerable applications



