PaperCut Warns of Zero-Day Vulnerability in NG and MF Actively Exploited, Urges Immediate Access Restriction

Views: 56 views

470/69 Friday, August 28, 2026

PaperCut has issued an urgent advisory after discovering that attackers are exploiting a vulnerability in PaperCut NG and PaperCut MF, enterprise print management software products. The attacks are being carried out as zero-day exploitation and affect all versions of the products. The company stated that customer environments have already been attacked and that it is investigating the incident as a top priority. PaperCut recommends that organizations with PaperCut Application Servers exposed to the internet immediately restrict access to the web interface to trusted IP addresses only through firewall rules or network access controls.

PaperCut has not yet disclosed technical details of the vulnerability or the method used by attackers. However, the company’s security team has been able to reproduce the issue based on information received from a university customer. PaperCut has also released an emergency patch for customers with PaperCut NG/MF servers exposed externally, especially in cases where other mitigation measures cannot be implemented immediately. In addition, PaperCut has published initial Indicators of Compromise (IoCs), including abnormal activity from the legitimate PaperCut process pc-app.exe and server.log files that have been modified, deleted, or are missing. Administrators are also advised to review related errors in those log files.

At this time, PaperCut has not identified the threat actor behind the attacks, what actions attackers took after compromising servers, or whether any data was exfiltrated. The company stated that it will provide further updates as the investigation progresses. PaperCut has previously been targeted by attackers, including through CVE-2023-27350 in 2023, which allowed unauthenticated attackers to bypass authentication and execute code on vulnerable servers.

Source: https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/