Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Summary

Threat actors are actively exploiting newly disclosed vulnerabilities in PaperCut software to steal credentials from educational institutions in the US and Europe. The attackers are leveraging an authentication bypass and remote code execution flaw to gain access and perform reconnaissance.

IFF Assessment

FOE

The exploitation of PaperCut flaws by threat actors to steal credentials directly harms defenders by compromising sensitive information and potentially leading to further network intrusion.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.

Defender Context

This article highlights a significant risk to educational institutions due to exploitable flaws in PaperCut software. Defenders should prioritize patching these vulnerabilities and monitoring their networks for signs of compromise. The targeting of the education sector suggests attackers are seeking valuable data or access points within these environments.

Read Full Story →