PaperCut NG/MF Zero-Day Under Active Attack
PaperCut confirms active exploitation of an unpatched flaw in all versions of NG and MF. Restrict web interface access now; emergency patches are available.

PaperCut issued an emergency security advisory on August 27, 2026, confirming that threat actors are actively exploiting a zero-day vulnerability in all versions of PaperCut NG and PaperCut MF. The company has verified “confirmed customer incidents” — this is not theoretical exposure, it is active intrusion.
No CVE has been assigned yet. PaperCut is withholding technical details about the vulnerability class while investigation continues, which is standard for an unresolved zero-day. What is confirmed: every version of both products is affected, exploitation is underway, and emergency patches are now available. Per the PaperCut security bulletin (August 27, 2026), the advisory is rated urgent.
What to do right now
Patch or block — pick one, do it now.
PaperCut has released emergency patches for public-facing server configurations. Identify your PaperCut installation type and apply the appropriate patch immediately. Full guidance and patch links are in the official advisory linked above.
If patching isn’t immediately possible, restrict network access to the PaperCut web management interface to trusted IP ranges via firewall rules. Do not leave the interface exposed to the internet or broad internal subnets while you’re scheduling the maintenance window. This is a mitigation, not a fix — it buys time, not safety.
Scope and why it matters
PaperCut NG and MF are print management platforms widely deployed in enterprise, government, and education environments. These systems typically sit on internal networks with broad access to document workflows, print queues, and user directories — the kind of network position attackers exploit for lateral movement after initial access. PaperCut has not disclosed what attackers are doing post-exploitation, but the deployment profile makes compromised servers a meaningful intrusion risk beyond the server itself.
Detection
PaperCut’s advisory identifies indicators of compromise for defenders to review, including abnormal activity related to the PaperCut application process and anomalies in server log files — specifically logs that have been modified, deleted, or contain unusual database error patterns. If you’re running PaperCut NG or MF and cannot patch immediately, review your server logs now for these signals.
Priority call
Patch this first. An unpatched, internet-accessible PaperCut server with confirmed active exploitation is an open door. The IP-restriction mitigation reduces exposure, but tight network segmentation alone is not a substitute for patching a zero-day with a confirmed track record of active use.
Watch the vendor bulletin for CVE assignment and additional technical detail as PaperCut’s investigation progresses.
Related: Yesterday’s Citrix NetScaler KEV deadline and the rConfig admin auth bypass are two more open patches competing for this week’s maintenance windows — stack-rank accordingly.
Found this useful? Share it.


