Attackers Used PaperCut to Hunt for Passwords Inside Schools and Universities
Update, 5 September 2026: Arctic Wolf told The Hacker News that it observed attackers using the PaperCut vulnerability chain against vulnerable servers at education organisations ranging from K-12 schools to major universities in the United States and Europe. The activity included command execution, reconnaissance, privileged-account creation, registry-hive collection, Meterpreter-related Java payloads and searches for credentials and other secrets in PaperCut configuration files.
The observations add campaign detail to PaperCut’s broader confirmation of active exploitation. They do not show that every education deployment is affected, that the campaign is limited to education, or that every compromised server was deliberately selected rather than found opportunistically.
PaperCut has now released PaperCut NG and MF 26.0.5, 25.0.13 and 24.1.10 as regular maintenance releases. They contain the fixes from all three emergency packages, add further security hardening and have completed PaperCut’s standard quality-assurance process. These releases replace the emergency patches. Customers running any emergency build should move to the matching maintenance release, while unpatched customers should upgrade immediately.
Update, 30 August: PaperCut now recommends a rebuild after suspected compromise
PaperCut expanded its incident guidance on 30 August with new indicators and a much stronger recovery position. If compromise is suspected, the vendor now recommends securing current backups, completely wiping and rebuilding the Application Server, and restoring a clean backup taken before the first suspicious behaviour. An in-place patch is not presented as sufficient incident recovery.
The updated indicators include five-character random file names written as <install>\server\lib\<name>.class, <install>\server\data\content\<name>.cmd and <install>\server\data\content\<name>.out. PaperCut also documented DB URL: jdbc:no:x DB Driver: <5-char random name> and related Derby strings in server.log. The company warns that attackers may clean up these files, so their absence does not rule out compromise.
Observed post-exploitation activity now includes pc-app.exe spawning cmd.exe, running whoami & ver, enumerating processes, domain controllers and logged-on users, and then downloading SimpleHelp and AnyDesk. Defenders should check for an unexpected Windows service named Remote Access Service running SimpleService.exe from C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted\, as well as unapproved AnyDesk installations.
At that stage, Release 2 was the current emergency package. PaperCut later superseded it with Release 3 and has now replaced all emergency packages with maintenance releases 26.0.5, 25.0.13 and 24.1.10. Site Servers and secondary or print servers must also receive the matching maintenance release.
Update, 31 August: CISA puts both PaperCut flaws on the KEV list
CISA added both CVE-2026-81578 and CVE-2026-82078 to its Known Exploited Vulnerabilities catalogue on 31 August. The catalogue feed was released at 14:55 UTC, or 16:55 Europe/Madrid. US federal civilian agencies have until 14 September 2026 to complete the required action.
The KEV entry removes any remaining ambiguity about operational priority. CISA requires organisations to apply the vendor’s mitigations, follow Binding Operational Directive 26-04 guidance for edge devices, and satisfy the agency’s forensic triage requirements for internet-facing systems. PaperCut’s own guidance remains stronger than a simple patch instruction: where compromise is suspected, preserve evidence, wipe and rebuild the Application Server, then restore from a clean backup that predates the suspicious activity.
The two catalogue entries are separate because each vulnerability crosses a different boundary. CVE-2026-81578 bypasses authentication and permits configuration changes. CVE-2026-82078 turns control of that configuration into arbitrary Java code execution. In the observed chain, the first flaw supplies the prerequisite for the second.
Update, 5 September: intruders searched education servers for credentials
Arctic Wolf’s Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut servers in education environments in the United States and Europe. The company provided the campaign findings to The Hacker News rather than publishing a separate public research report.
Observed actions included the discovery commands uname, whoami, ver and tasklist, plus creation or attempted creation of a privileged account named Administrator17. Attackers staged harvested system and user information in files under /custom/ paths and retrieved them from an external address.
Arctic Wolf also identified delivery of the tools lsa_collect.exe, lsa_collect_small.exe and save_hives.exe through certutil.exe. In sandbox analysis, lsa_collect.exe extracted registry keys used to reconstruct the Windows BootKey and reach the Security Account Manager database. Separate Java payloads were associated with Metasploit and Meterpreter.
The intruders used findstr to search PaperCut *.config files for terms including password, secret, ldap, bind and token. That behaviour turns the incident from control of a print server into a credential-exposure problem that may reach other systems connected to the same identities.
This activity is distinct from the earlier PaperCut sequence documented in this article, which included SimpleHelp and AnyDesk deployment. Both sets of observations follow exploitation of the same vulnerable product family, but defenders should hunt for each tool chain separately rather than treating one as proof that the other did or did not occur.
What changed after the first emergency patch
The original bulletin confirmed exploitation but did not name the vulnerable components or assign CVE identifiers. The updated disclosure now identifies an authentication bypass and an unsafe dynamic class-loading flaw. Used together, they allow an unauthenticated attacker to change trusted configuration and execute code inside the PaperCut Application Server process.
| Vulnerability | Impact and prerequisites | Current fix and exploit status |
|---|---|---|
| CVE-2026-81578 Authentication bypass CVSS 8.8 | Specially crafted unauthenticated requests can cause administrative backend actions to run before access validation completes, allowing a remote attacker to modify certain system configurations. | Fixed in maintenance releases 26.0.5, 25.0.13 and 24.1.10, which replace all emergency packages. PaperCut confirms active exploitation of the chain. Huntress reproduced the bypass in a complete proof of concept. |
| CVE-2026-82078 Unsafe dynamic class loading CVSS 9.4 | PaperCut’s database utilities instantiate driver classes from configurable names without restricting them to an allowlist. Control of the relevant configuration can lead to arbitrary Java bytecode execution in the PaperCut server process. | Fixed in maintenance releases 26.0.5, 25.0.13 and 24.1.10, which replace all emergency packages. PaperCut confirms active exploitation of the chain. The authentication bypass can supply the configuration-control prerequisite and produce unauthenticated code execution. |
Huntress has a working proof of concept for the complete chain but has not published exploit code. Its researchers demonstrated a remote request causing charmap.exe to run as SYSTEM under pc-app.exe on a stock PaperCut NG installation.
PaperCut says the regular maintenance releases contain all security fixes from Emergency Patch Releases 1, 2 and 3, plus additional hardening. The current remediation message is therefore unambiguous: move version 26 to 26.0.5, version 25 to 25.0.13 or version 24 to 24.1.10. An emergency Release 3 build still contains the disclosed fixes, but it is no longer the current supported destination.
What attackers did after reaching the server
Huntress observed two exploitation incidents. Activity in one environment on 26 August lasted less than two minutes. Base64-encoded commands decoded to whoami & ver, identifying the account and Windows version. A second incident on 27 August added tasklist to enumerate running processes.
The attackers also delivered an operating-system-independent Java class file. Huntress recovered Udydn.class and another copy named Moo97.class from a PaperCut installation. The code could run commands on Windows or Linux, collect a directory listing and write the results to Udydn.out.
The payload then deleted its output, PaperCut’s server.log and the Derby database log. That behaviour makes evidence preservation important. A restart, hurried cleanup or in-place upgrade can remove context needed to determine what happened before the patch.
Huntress’s reproduced chain used an attacker-controlled SMB2 share to deliver the Derby archive. Where business requirements allow, defenders should restrict or closely monitor outbound SMB from the PaperCut server.
Current maintenance-release coverage and component guidance
| Environment | Required action |
|---|---|
| PaperCut NG or MF version 24, 25 or 26 | Install maintenance release 26.0.5, 25.0.13 or 24.1.10 for the matching branch. These regular releases replace Emergency Patch Releases 1, 2 and 3. |
| PaperCut NG or MF version 23 or earlier | Migrate to a currently supported branch and then install its current maintenance release. |
| Site Servers and secondary or print servers | Install the matching current maintenance release on these components as well as the primary Application Server. |
| Print Deploy and Mobility Print | PaperCut says these components are not affected and do not require this emergency update. |
| External database used for Card or ID lookups | Follow PaperCut’s current configuration guidance. Release 3 restores support for legacy Microsoft SQL Server drivers while retaining the security changes introduced in Release 2. |
| SAML authentication | The regular maintenance releases contain the regression fixes first delivered in Emergency Patch Release 3. |
PaperCut still instructs administrators to restrict internet-facing Application Server interfaces to trusted IP addresses. The maintenance releases add further hardening and have completed the vendor’s standard quality-assurance process. Patching closes the reported paths but does not prove that a previously exposed server was never compromised.
Indicators and evidence to preserve
- Child processes, command execution or unusual network connections originating from
pc-app.exe. - Missing, unexpectedly truncated or deleted
server.logor Derby log files. - Files named
Udydn.class,Moo97.class,Udydn.outorUdydn.cmdunder the PaperCut server directory. - The encoded command strings associated with
whoami & verorwhoami & ver & tasklist. DB URL: jdbc:derby:memory:pwnnear a large encoded data blob.ERROR No suitable driver found for jdbc:no:x.ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.- Unexpected outbound SMB connections from the PaperCut server.
- Account creation involving
Administrator17. - PaperCut child processes invoking
certutil.exe,findstr,cmd.exe,powershell.exeor other command interpreters. - Files or execution involving
lsa_collect.exe,lsa_collect_small.exeorsave_hives.exe. - Requests for
/custom/pcp_*.txtor/custom/web/pcp_*.txt. - Java payload retrieval or Meterpreter-related traffic from the PaperCut server.
- Searches across
*.configfiles forpassword,secret,ldap,bindortoken.
PaperCut warns that the absence of its published indicators does not prove a system is unaffected. Preserve the full PaperCut logs directory and file metadata, current and non-default configuration, endpoint process trees, reverse-proxy records, firewall and DNS telemetry, recent services, scheduled tasks, autoruns and file creation events.
What defenders should do now
- Remove public exposure. Restrict PaperCut web interfaces to trusted addresses or a controlled access path.
- Install the current maintenance release. Move version 26 to 26.0.5, version 25 to 25.0.13 or version 24 to 24.1.10 on every applicable component, including Site Servers and secondary or print servers.
- Upgrade unsupported branches. Move version 23 and earlier to a currently supported and patched release.
- Preserve evidence before changing the host. Collect logs, file metadata, process telemetry and network records before a restart or rebuild where incident-response requirements allow.
- Hunt both observed tool chains. Check for the earlier SimpleHelp and AnyDesk activity as well as the education-sector observations involving
Administrator17, registry-hive tools, configuration searches and Meterpreter-related Java payloads. - Rotate potentially exposed secrets after scoping. Include local and service accounts, LDAP bind credentials, database credentials, tokens and other secrets reachable from the PaperCut server.
- Rebuild suspected compromises. Follow PaperCut’s guidance to wipe and rebuild the Application Server and restore a clean backup that predates suspicious activity.
The BlackTree view
The operational lesson is not simply that PaperCut had two vulnerabilities. The first emergency patch arrived while exploitation was already happening, researchers then found ways around it, and subsequent investigations showed attackers using the access to search education servers for credentials.
Emergency updates compress testing time, but they do not lower the standard for verification. Administrators need to confirm the exact release installed on every server component, preserve evidence from the exposure window and keep network containment in place until the investigation is complete.
Update, 10 September: the full chain takes less than five seconds
watchTowr has now published a full end-to-end analysis of the exploitation chain for CVE-2026-81578 and CVE-2026-82078. Its sensors recorded more than 1,000 attempts from activity spanning over ten geographies. A successful chain reached remote code execution in less than five seconds and restored the changed configuration afterwards, reducing the obvious traces of the initial access.
The post-exploitation detail changes the incident-response priority. watchTowr observed an in-memory Jetty servlet filter carrying Godzilla command-and-control functionality, together with the suo5 HTTP proxy. In one sequence, hands-on-keyboard file reads began 18 seconds after the implant was installed.
The operators were also adaptive. One implant attempt failed, the attacker corrected the problem and returned 52 minutes later with a working approach. That behaviour is inconsistent with treating every request as blind commodity scanning.
Capture memory before restart
A restart can remove the volatile in-memory implant and destroy some of the best evidence that it existed. Organisations investigating an exposed, unpatched PaperCut server should capture JVM memory or a heap dump before restarting when their response process and operational risk allow it. After evidence capture, patch, restart and continue the compromise assessment.
- Assume an internet-exposed server that remained vulnerable during the campaign may have been compromised.
- Preserve JVM memory, process, network and application evidence before a restart where feasible.
- Use watchTowr’s published URI and request-body indicators to search web, proxy and application logs.
- Look for Jetty servlet-filter modification, Godzilla traffic patterns, suo5 proxy activity and rapid file reads after exploitation.
- Patch and restart after evidence capture, then verify that no persistent access, credentials or downstream sessions remain.
The patch closes the vulnerable path. It does not remove a web shell that was already loaded into memory, explain earlier outbound connections or invalidate credentials an operator may have collected.
Update, 11 September: hundreds of AI agents turned minutes into seconds
GreyNoise has now documented a separate view of the PaperCut campaign that shows what happened when exploitation moved from fast scripts to agentic orchestration. The company says a likely Russian-speaking malicious actor used hundreds of AI agents to develop, test and deploy exploits for CVE-2026-81578 and CVE-2026-82078.
GreyNoise identified at least 440 compromised PaperCut instances belonging to 395 organisations in 48 countries. Once the full campaign began, the actor compromised at least 11 organisations in 26 seconds. In one US high school, the path from initial access to domain administrator took seven minutes.
Those figures do not mean that every compromised server led to control of its Windows domain. GreyNoise observed domain-administrator access at 12 organisations. At the other identified victims, the actor had not reached that level by the end of the observation period.
The agents were not simply scanning a fixed list. GreyNoise says the actor first built a PaperCut and Active Directory laboratory, developed remote-code-execution and credential-harvesting workflows, and assembled targets using an internet-scanning service. The campaign then ran those tasks in parallel against public systems.
The move from PaperCut to domain control followed three observed routes. Attackers extracted LSASS memory and registry secrets to recover privileged credentials, used the older noPac vulnerabilities against unpatched Active Directory environments, or took advantage of PaperCut servers that were themselves domain controllers or ran under a domain-administrator service account. The final step included DCSync and exfiltration of the domain credential database.
The actor tried to exclude organisations in 28 countries, but GreyNoise says some agents still compromised systems on the exclusion list. That is evidence that the orchestration did not always follow its operator’s stated constraints. It is not evidence that the agents independently chose the campaign or its objectives.
Traditional controls still interrupted the attack. GreyNoise reports that Cloudflare’s web application firewall blocked at least one attempt. That does not make a WAF a substitute for installing PaperCut’s fixed maintenance releases, but it shows that ordinary exposure reduction, traffic inspection and segmentation can still break an AI-assisted sequence.
- Move PaperCut NG or MF to the current maintenance release rather than relying on an earlier emergency patch.
- Search for GreyNoise’s published infrastructure, hashes, account name
Administrator17, registry-hive staging paths and DCSync activity. - Review whether the PaperCut service account is privileged in Active Directory and whether the server has a role on a domain controller.
- Confirm that domain controllers are protected against CVE-2021-42278 and CVE-2021-42287, which GreyNoise observed as one route to domain control.
- Preserve memory and application evidence before restart where operationally safe, then follow PaperCut’s rebuild guidance for suspected compromise.
The operational change is not that artificial intelligence made patching irrelevant. It made an exposed patch gap much easier to exploit at scale and compressed the time between one successful test and hundreds of intrusions. The defensive answer remains familiar, but the acceptable delay has become much shorter.
Sources
- PaperCut urgent security bulletin. Initially published 27 August 2026 with no time provided. PaperCut published maintenance releases 26.0.5, 25.0.13 and 24.1.10 on 10 September at 14:00 AEST, or 06:00 Europe/Madrid. The advisory was last updated 10 September 2026.
- The Hacker News: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities, published 5 September 2026. The page provides no publication time. Arctic Wolf supplied the campaign observations directly to the publication.
- Huntress investigation and proof-of-concept analysis, published 27 August 2026.
- CISA Known Exploited Vulnerabilities catalogue, feed release 31 August 2026 at 14:55 UTC, or 16:55 Europe/Madrid. Both vulnerabilities have a federal remediation deadline of 14 September 2026.
- watchTowr, published 9 September 2026. The page provides no exact publication time.
- GreyNoise: AI-orchestrated campaign against PaperCut NG/MF, published 9 September 2026. The page provides no exact publication time.


