Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control
August 28, 2026
Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks
August 28, 2026
GitLab Patches Critical AI Agent Flaw Allowing Code Execution
August 27, 2026
Home/Vulnerabilities/Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks
Vulnerabilities

Critical PaperCut NG/MF Vulnerability Actively Exploited in Attacks

Key Takeaways An unpatched vulnerability in PaperCut NG and MF print management software is under active exploitation. All supported versions are affected, regardless of specific version numbers....

Marcus Rodriguez
Marcus Rodriguez
August 28, 2026 3 Min Read
2 0

Key Takeaways

  • An unpatched vulnerability in PaperCut NG and MF print management software is under active exploitation.
  • All supported versions are affected, regardless of specific version numbers.
  • PaperCut has released emergency patches and urges immediate network restrictions for internet-facing servers.
  • The vulnerability has been confirmed through customer incidents and internal reproduction.
  • Security teams should actively monitor for specific indicators of compromise.

PaperCut, a prominent provider of print management solutions, has confirmed that an unpatched vulnerability within its widely deployed PaperCut NG and PaperCut MF software is being actively exploited by attackers. This critical development prompted the company to issue an urgent security advisory and subsequently release emergency patches within hours of its initial warning.

Table Of Content

  • Key Takeaways
  • Immediate Mitigation Urged
  • What You Should Do

The Australian vendor’s security response team is actively investigating “confirmed customer incidents” related to this flaw, which it is treating with the highest priority. While a formal CVE identifier has not yet been assigned, the urgency of the situation underscores its severity.

According to PaperCut cautioned, the vulnerability impacts all currently supported versions of both PaperCut NG and PaperCut MF. This means that organizations running any supported release are exposed, making specific version numbers irrelevant to the risk profile.

The issue came to PaperCut’s attention via the internal security and digital forensics teams of a university customer. Their findings enabled PaperCut engineers to successfully reproduce the bug and confirm its active exploitation in the wild, prompting the swift response.

While the technical specifics of the vulnerability’s root cause remain undisclosed as the investigation continues, the rapid deployment of an emergency build on the same day as the initial alert strongly suggests a serious remote exploitation vector, particularly against internet-facing servers.

Immediate Mitigation Urged

PaperCut is strongly advising all customers with an Application Server accessible from the public internet to immediately implement network access controls. This involves restricting access to trusted IP ranges, such as internal networks, using firewall rules or equivalent security measures.

The company emphasized the critical importance of taking these steps immediately, even if no suspicious activity has been observed. The absence of warning signs does not guarantee a system’s safety from potential compromise.

Security teams are also encouraged to proactively hunt for potential signs of compromise. Indicators include suspicious post-exploitation activity originating from the pc-app.exe process, server.log files that are unexpectedly missing or truncated, and specific log entries containing “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST.”

However, PaperCut cautioned that the absence of these specific artifacts does not definitively rule out a breach. The company plans to publish validated indicators of compromise as its investigation progresses and more information becomes available.

At 2:10 a.m. AEST on August 28, 2026, PaperCut released emergency, out-of-cycle builds for both the v25 and v26 branches of NG and MF. These updates cover Windows, Linux, and macOS installers.

These releases are explicitly labeled as emergency builds, distinct from standard software updates. They are specifically intended for administrators operating public-facing servers who cannot otherwise isolate their systems from direct internet exposure. A build for the older v24 branch is currently under development, and PaperCut is urging all customers to upgrade to the latest available version whenever feasible.

This is not the first instance of PaperCut’s print management platform attracting the attention of threat actors. In 2023, an authentication bypass flaw, identified as CVE-2023-27351, was actively exploited by ransomware affiliates and was subsequently added to CISA’s Known Exploited Vulnerabilities catalog earlier this year.

Given this history, cybersecurity researchers anticipate that this newest vulnerability will rapidly draw the attention of opportunistic attackers scanning for exposed servers. Consequently, prompt patching and robust network segmentation are deemed essential for any organization utilizing PaperCut in a production environment.

What You Should Do

  • Immediately restrict public internet access to your PaperCut Application Server using firewall rules or network access controls, allowing only trusted internal IP ranges.
  • Apply the emergency patches released by PaperCut for v25 and v26 branches as soon as possible. If running v24, monitor for the upcoming patch and upgrade to the latest available version.
  • Proactively hunt for indicators of compromise (IoCs) such as suspicious pc-app.exe activity, truncated server.log files, or specific error messages in logs.
  • Subscribe to PaperCut’s security advisories for updates and validated IoCs.
  • Review and strengthen your overall network segmentation strategy to minimize exposure of critical services.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitHackerPatchransomwareSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

GitLab Patches Critical AI Agent Flaw Allowing Code Execution

Next Post

Critical cPanel Vulnerability (CVE-2023-XXXX) Allows Full Server Control

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Kasa Smart Home Vulnerability Lets Attackers Disrupt Devices
August 27, 2026
CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
August 27, 2026
Two Australians Charged for TeamPCP Supply Chain Attacks
August 27, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us