CuraSec

Act active

PaperCut Auth Bypass + RCE Chain Exploited for Credential Theft in Education

2026-09-05 13:51 UTC · The Hacker News · read the source ↗ #papercut#credential-theft#active-exploitation
  • Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation chaining an auth bypass into RCE. Identify your PaperCut version immediately and patch to the vendor-specified fixed release; treat as critical given the exploitation chain severity.
  • SOC/IR — Act: An active credential-theft campaign is exploiting PaperCut installations, with command execution and reconnaissance observed. Hunt for post-authentication anomalies in PaperCut server logs and sweep for Arctic Wolf’s published IOCs dating back to the initial disclosure window.
  • Leader — Plan: Verify whether PaperCut is deployed anywhere in your estate and confirm engineering is treating remediation as priority given CISA KEV listings and active credential harvesting; education-sector orgs face the highest exposure.
  • Signals: CVE-2026-81578 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub · CVE-2026-82078 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.