PaperCut warns of unpatched flaw in print software exploited in zero-day attacks
PaperCut said hackers are exploiting a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software.
Source: BleepingComputer · August 27, 2026 at 11:31 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 28 AUGUST 2026 —
PaperCut said hackers are exploiting a zero-day vulnerability in all versions of its PaperCut NG and PaperCut MF print management software.
Market Impact
The company confirmed active attacks on customers and urged organisations with internet-facing PaperCut Application Servers to restrict web interface access to trusted IP addresses immediately.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” it said in a security advisory published on Thursday.
“We are aware of confirmed customer incidents and are treating this matter with the highest priority.”
The flaw affects every installation of PaperCut NG and MF, but the company has not revealed technical details or exploitation methods.
PaperCut’s security team reproduced the vulnerability using information supplied by a university customer.
Emergency patches are now available for servers exposed to the internet.
“This is an emergency patch for customers with public-facing PaperCut NG/MF servers who are unable to take other mitigating action,” the advisory said.
PaperCut repeated its call for customers to block public access to the web interface using firewall rules or network access controls.
It also published indicators of compromise that may signal a compromise.
These include suspicious activity from the legitimate PaperCut pc-app.exe process and server.log files that have been modified, deleted or are missing.
Administrators should look for the following errors in server.log:
PaperCut cautioned that the absence of indicators does not guarantee a server remains uncompromised.
So far, PaperCut has not identified who is behind the attacks, what intruders do after gaining access, or whether data is being stolen.
The company said it will update the advisory with additional indicators and remediation guidance as its investigation proceeds.
BleepingComputer contacted PaperCut with questions and said it will update the story when it receives a response.
PaperCut has a history of being targeted after vulnerabilities are disclosed.
In April 2023, attackers began exploiting the critical CVE-2023-27350 PaperCut flaw, which allowed unauthenticated attackers to bypass authentication and remotely execute code.
Microsoft later linked some of those attacks to the Clop ransomware operation, which used vulnerable PaperCut servers for initial access to company networks.
Microsoft also observed intrusions that led to LockBit ransomware attacks.
While PaperCut has a Print Archiving feature that can retain documents sent through a server, Clop told BleepingComputer it exploited the flaw only for initial access rather than to steal archived documents.
Exploitation spread to other threat actors, with Microsoft reporting that Iranian state-backed hacking groups also exploited CVE-2023-27350.
CISA and the FBI issued a joint advisory in May 2023 warning that the Bl00dy Ransomware Gang was exploiting vulnerable PaperCut servers in attacks against the education sector.
Related: PaperCut Software · Kuala Lumpur