Home/Blog/PaperCut auth-bypass + RCE chain exploited in schools
blog

PaperCut auth-bypass + RCE chain exploited in schools

September 7, 2026 · Security News

Attackers are chaining two flaws in PaperCut NG and MF — CVE-2026-81578 and CVE-2026-82078 — to bypass authentication and run code on print-management servers. Schools and universities are being hit first: attackers steal credentials, create privileged accounts and drop malware.

What happened

PaperCut runs the print infrastructure for a huge number of organisations, and its server sits quietly on the internal network with broad reach. The chain pairs an authentication bypass (CVE-2026-81578) with a remote code execution flaw (CVE-2026-82078): the first gets the attacker in without valid credentials, the second turns that access into control of the server. Education is the current target because it runs PaperCut widely and patches slowly.

PaperCut has a track record here. It was a marquee ransomware entry point in 2023, and the pattern repeats: a trusted internal appliance nobody thinks of as a security boundary becomes the doorway.

Why it matters

A print server is a soft, trusted box in the middle of your network, which makes it an ideal pivot. Once an attacker owns it they harvest credentials, mint admin accounts and move laterally toward the data and backups that matter. Finding these forgotten internal footholds before an attacker does is the whole point of an internal network penetration test, while the exposed side is covered by external network penetration testing.

What to do now

  • Patch PaperCut NG and MF to the fixed versions immediately, and take the admin interface off the public internet.
  • Assume compromise if it was reachable: review accounts for ones you did not create, check for new admins and scheduled tasks.
  • Bring PaperCut and other ‘boring’ internal servers into your vulnerability management scope.
  • Put detection on the internal network with a managed SOC, and if you find an intrusion, contain it with compromised server recovery.

The takeaway

The most dangerous box on your network is usually the one nobody calls a security product. Print servers, RMM, appliances: they are trusted, under-patched and internet-adjacent. Treat them as the boundaries they actually are, and test what an attacker could reach from them, ideally before someone does it for you. A penetration test answers that question directly.

← All articles

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.