Arctic Wolf’s researchers watched the same chain land on school after school. An authentication bypass, then remote code execution, then credential theft. The box in the middle was PaperCut, the print-management appliance that sits next to Active Directory and looks, to most campus cybersecurity programs, like furniture. CVE-2026-81578 and CVE-2026-82078 turned that furniture into a login harvester across the U.S. and Europe.

You already know the pattern if you’ve inherited a university network. The print server is the machine nobody wants to own. It talks to every lab, every staff VLAN, every student laptop that ever hit print. It has a web console. It stores usernames because quotas and billing demand it. Attackers did not invent a new campus story. They picked the box that already held a directory relationship and found it listening.

Illustration of print-management software being used in attacks against schools and universities
Print managers sit beside campus directories. Arctic Wolf saw attackers turn that trust into credential theft at schools in the U.S. and Europe.

PaperCut Already Sat Next to Active Directory

Print management software is an identity broker that happens to spool jobs. It authenticates users, caches group membership, talks to LDAP or Active Directory, and exposes an admin interface that campus IT files under facilities. Arctic Wolf’s Adversary Research Team watched operators chain the new flaws for command execution and reconnaissance, then pull credentials. Once you stop calling it a printer, that is the entire job of the appliance.

Schools and universities make this class of box easy. Semester turnover floods the directory with new accounts. Labs stay open at odd hours. The print portal is often the one service students reach from dorm Wi-Fi and from off-campus housing. When that portal sits on the public internet, your firewall is already treating a directory-adjacent appliance like a brochure site. Brute-force noise against a login form was the old problem. An authentication bypass plus remote code execution skips the form and hands over a shell.

You’ll see the same failure in systems you do not operate. Trezor told U.S. customers their shipping records were gone. ShipMonk still had them. Names, emails, phone numbers, shipping addresses, and order numbers from November 2019 through August 2021, about 67,000 people. The hardware wallets were fine. The warehouse platform that was supposed to forget them was not. Operational plumbing keeps secrets long after the product team files the deletion ticket.

Trezor hardware wallet, whose shipping vendor still held customer records the company said were deleted
Trezor said U.S. shipping records were deleted. ShipMonk still held details on about 67,000 customers from 2019 to 2021.

Campus Cybersecurity Still Counts Printers as Furniture

Stop classifying print, copy, scan, and quota systems as peripherals. They are directory clients with a web stack. The immediate work is unglamorous, and it is the only threat-protection that matters on a host your EDR never enrolled.

Pull an inventory this week. Every PaperCut instance, every competing print manager, every copier with an embedded web OS. Record the version, the identity backend, whether the user portal and the admin UI are reachable from the internet, and who holds the break-glass account. Common PaperCut web ports are 9191 and 9192; if those answers include a public A record, you have an identity system on the open net. If you cannot prove the patches for CVE-2026-81578 and CVE-2026-82078 are installed, treat the host as compromised until you can. Move user-facing print portals off the public internet. Put them behind campus SSO or a VPN you already log. Admin consoles do not belong on student Wi-Fi.

Security hardening on the box itself is the same work you already do on jump hosts. Disable unused connectors. Kill default accounts. Restrict the service account to the OU it actually needs. Log authentication failures and successes. Defense in depth here is deliberately boring: segment the print VLAN, deny the appliance outbound internet except a named update channel, and enroll the OS in the same telemetry you trust for servers. If you cannot enroll it, replace it. A print host that is invisible to threat detection is a domain-adjacent blind spot with a friendly hostname.

Keep the pressure on after the emergency change window. Version-pin every print manager in the CMDB. Vendor advisories for internet-reachable instances get an hour-scale ticket, not a weekly CAB. Alert on new local users, new child processes, and LDAP or Kerberos traffic from the print host that does not match a job. Cyber security programs that still file printers under facilities will keep losing the directory through the copier.

Hunt the Queue the Way You Hunt a Domain Controller

If this chain is in your environment, incident response starts on the print host, not in the helpdesk queue of failed student logins. Snapshot the appliance. Pull the web logs, the service logs, and the identity-connector logs. Hunt for unauthenticated admin-equivalent requests, then command execution, then outbound reconnaissance. Credentials that flowed through the box are burned: the bind account, cached staff and student secrets, any API token the connector used. Rotate them from the directory side. Then look for persistence on the host and for follow-on authentication in AD sourced from the print server’s IP.

Do not close the ticket when the portal comes back. Watch the quiet week after. New printer-admin users. Scheduled tasks that were not there on Monday. Unexpected SMB or LDAP from the appliance. MFA prompts against accounts that first showed up in print logs. Facilities will reboot the copier. The vendor will ship a fix. You treat the queue as a privileged identity system, or you will do this again next semester when the next pair of CVEs lands.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.