Act
active
PaperCut Auth Bypass + RCE Chain Exploited for Credential Theft in Education
- Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation chaining an auth bypass into RCE. Identify your PaperCut version immediately and patch to the vendor-specified fixed release; treat as critical given the exploitation chain severity.
- SOC/IR — Act: An active credential-theft campaign is exploiting PaperCut installations, with command execution and reconnaissance observed. Hunt for post-authentication anomalies in PaperCut server logs and sweep for Arctic Wolf’s published IOCs dating back to the initial disclosure window.
- Leader — Plan: Verify whether PaperCut is deployed anywhere in your estate and confirm engineering is treating remediation as priority given CISA KEV listings and active credential harvesting; education-sector orgs face the highest exposure.
- Signals: CVE-2026-81578 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub · CVE-2026-82078 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.