PaperCut flaws reportedly exploited against schools in the United States and Europe

BRIEF
A supplied security report says attackers are exploiting two recently disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks against schools and other education organizations in the United States and Europe. The report says the activity is intended to steal credentials and gain privileged access. The supplied verification note describes exploitation against schools and says compromise of education systems and privileged credentials creates clear public-service impact. It does not provide a count of affected organizations, identify specific victims, explain how many systems were compromised, or describe confirmed data theft or service disruption. Those details remain uncertain. The immediate security concern is the combination of an administrative application, active exploitation, credential theft, and privileged access. Education organizations should identify PaperCut deployments, establish whether the cited versions or configurations are present, apply available vendor guidance where applicable, and investigate authentication and administrator activity for signs of misuse. Organizations should avoid assuming that an absence of visible disruption means no credentials or privileged access were affected.
WHY IT MATTERS
PaperCut sits in an operational environment where compromise could affect printing services, accounts, or administrative access, although the supplied facts do not confirm specific consequences for any victim. The reported exploitation changes the priority from routine vulnerability management to active exposure assessment. Schools and other organizations should determine whether they run the affected software, review authentication and administrator logs, and look for credential misuse. The number and identity of affected organizations remain unknown from the supplied information.