HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Authentication Bypass and RCE in PaperCut MF/NG (CVE‑2026‑81578, CVE‑2026‑82078) Enables Credential Theft in Schools

Threat actors are exploiting two newly disclosed PaperCut flaws—an authentication bypass and a remote code execution chain—to harvest administrator credentials from schools and universities. The incident highlights the need for strong access‑control monitoring and third‑party patch governance.

Verisq™ Intelligence · 📅 September 05, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Authentication Bypass and Remote Code Execution in PaperCut MF/NG (CVE‑2026‑81578, CVE‑2026‑82078) Enable Credential Theft in Education Organizations

What It Is — PaperCut released two critical flaws: CVE‑2026‑81578 (authentication bypass) and CVE‑2026‑82078 (remote code execution). Together they allow an unauthenticated attacker to execute commands on the print‑management server and harvest administrator credentials.

Exploitability — The Arctic Wolf Adversary Research Team has observed active exploitation in the wild, targeting schools and universities in the U.S. and Europe. Both CVEs have public PoCs and a CVSS v3.1 base score of 9.8 (Critical).

Affected Products — PaperCut MF and PaperCut NG on Windows and Linux servers (versions prior to the September 2026 security patch).

Why It Matters for Trust & Control Assurance

  • Access‑control integrity – An authentication bypass directly violates the control objective of ensuring only authorized users can access privileged functions.
  • Continuous evidence – Detecting anomalous command execution and credential‑theft activity requires robust logging and real‑time monitoring to provide defensible audit trails.
  • Third‑party risk – Relying on unmanaged print‑management software expands the attack surface; demonstrating due‑diligence over vendor patches is a key trust signal for auditors and partners.

Recommended Actions

  1. Apply PaperCut’s September 2026 security update immediately.
  2. Verify that all print‑management servers are running a patched version; inventory any legacy instances.
  3. Enforce multi‑factor authentication for all PaperCut admin accounts and rotate compromised credentials.
  4. Enable detailed command‑execution logging and integrate logs into a SIEM for continuous monitoring.
  5. Review third‑party risk documentation to confirm that vendor patch management processes meet your control‑assurance requirements.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →