Hackers exploit print-server flaws to steal credentials from U.S. and European schools
Federal officials and independent researchers say attackers are chaining two flaws in the widely used PaperCut print-management platform to break into school and university networks, with intrusions escalating from automated scans to hands-on-keyboard attacks.

Federal cybersecurity officials have confirmed that hackers are actively breaking into school and university computer networks across the United States and Europe by exploiting two flaws in PaperCut, a print-management program used at more than 70 percent of the world's universities and by tens of thousands of K-12 school districts. Security researchers say the intrusions have escalated in the past two weeks from automated scanning to hands-on-keyboard activity, with intruders creating administrator accounts, harvesting Windows credentials and probing compromised networks for higher-value targets.
The Cybersecurity and Infrastructure Security Agency added both flaws, tracked as CVE-2026-81578 and CVE-2026-82078, to its Known Exploited Vulnerabilities catalog on August 31, setting a September 14 deadline for federal civilian agencies to patch or disconnect exposed systems. Chained together, the two bugs let an attacker with no valid credentials reach a PaperCut application server over the internet, rewrite its configuration, and execute arbitrary code on the underlying host — full remote compromise, with no password required at any stage.
How the attack chain works
PaperCut disclosed the flaws in an urgent security bulletin on August 27, after a customer in the education sector reported a compromised server. CVE-2026-81578, rated 8.8 out of 10 on the CVSS severity scale, is a missing-authentication flaw in PaperCut's web management interface that lets an unauthenticated remote attacker alter system configuration settings. CVE-2026-82078, rated 9.4, is an unsafe dynamic class-loading bug in the software's database connection utilities that lets an attacker who has already tampered with the configuration load and run arbitrary Java code under the security context of the PaperCut server process.
Melbourne-based PaperCut, whose software is embedded in the print queues of schools, hospitals and government agencies worldwide, said the authentication-bypass component "came from code I personally have contributed to over the years," according to an internal account of the incident response posted to the company's engineering blog. The company said it declared its highest-severity internal incident within hours of the first customer report, at 9:42 a.m. Australian Eastern time on August 27, and chose to ship interim protections rather than wait for what it called "a single perfect fix while customers remained exposed."
The numbers
- More than 1,000 PaperCut NG/MF servers remain reachable from the open internet worldwide, concentrated in North America and Europe, according to exposure data cited by researchers at the security firm WatchTowr.
- PaperCut has shipped three successive emergency patches — Releases 1 through 3, the last published September 1 — after researchers found that earlier fixes could be bypassed.
- CISA's remediation deadline for federal agencies is September 14; the education sector, which is not bound by the federal directive, has no comparable deadline.
- Confirmed exploitation targeting Active Directory credentials in schools and universities has continued since at least September 3, according to incident responders at Arctic Wolf.
Who is affected
PaperCut's customer base skews heavily toward education because the software manages shared printing and per-user quotas across large populations of students and staff — precisely the kind of institutional network, tied into a central Active Directory system, that makes a compromised print server valuable to an intruder. Security firm Arctic Wolf said in research published this month that attackers chaining the two flaws have targeted organizations "ranging from K-12 schools to major universities" in the United States and Europe, using the compromised print servers as a foothold to harvest domain credentials that could open a path into other campus systems, including student records and research networks.
Outside education, any organization running an internet-facing PaperCut NG or MF application server is at risk, including local governments, healthcare providers and manufacturers that use the platform to manage print costs. Researchers at Rapid7 and other firms have said the vulnerable population extends well beyond schools, though the confirmed intrusions reported so far have clustered in the education sector.
"The authentication bypass component came from code I personally have contributed to over the years," PaperCut said in an account of its incident response posted to the company's own engineering blog, adding that it declared its highest-severity internal incident within hours of the first customer report rather than wait for "a single perfect fix while customers remained exposed."
Reaction
Incident responders have urged system administrators to treat any internet-exposed, unpatched PaperCut server as already compromised rather than assuming a patch alone will clear an intrusion. Researchers at the security firm WatchTowr, quoted across multiple outlets covering the intrusions, have said organizations should be assumed compromised if their servers were exposed before patching, warning that patching alone locks out new attackers while leaving ones already inside untouched. Arctic Wolf's researchers said observed post-exploitation activity has included delivery of Windows registry-hive collection tools, Metasploit-linked Java payloads, and commands to enumerate hosts, user accounts and stored credentials — standard reconnaissance steps that precede broader network compromise.
PaperCut has continued to revise its guidance as new bypass techniques surface. The company's advisory now tells customers with public-facing servers to restrict web access to trusted IP addresses immediately, using firewall rules or equivalent network controls, rather than relying on patching alone. CISA's catalog entry directs federal agencies to follow its binding directive on risk-based patching and to evaluate whether any exposed asset should be taken offline entirely if a fix cannot be applied quickly.
What happens next
The federal patching deadline of September 14 applies only to civilian executive-branch agencies, but CISA has said all organizations, public and private, should treat the flaws with the same urgency given evidence of active, ongoing exploitation. School districts and universities — many of which run lean IT security teams relative to the size of their networks — face a narrower window than most federal agencies to apply the emergency patches, restrict internet exposure and audit Active Directory logs for signs of credential theft before students return in full for the fall term. Security researchers say further investigation into the scope of the credential theft, including whether any stolen logins have been used to move into other campus systems, is likely to continue in the coming weeks.



