Live Situation โ Last checked: August 27, 2026 (Patch Now Available)
This is a fast-developing story. A critical zero-day PaperCut NG MF vulnerability is being actively exploited in the wild. While no formal CVE is assigned yet, PaperCut has just released an emergency patch as of 2:10 AM AEST (Aug 28). We are monitoring the official bulletin and will update this article as new IOCs are confirmed.
By Uday Patil, Cybersecurity Analyst | Last Updated: August 27, 2026
PaperCut has confirmed that cybercriminals are actively abusing an undisclosed vulnerability in its widely deployed print management solutions. The threat is severe enough that the Australian vendor rushed out an emergency patch just hours after its initial warning.
PaperCut software is deployed across more than 70,000 organizations and 100 million users worldwide, spanning schools, universities, government offices, and enterprises โ making this one of the most widely-deployed print management platforms globally.

According to the official security response team, the flaw impacts every currently supported version of the software. Whether you are running older legacy builds or the latest update, your system is exposed if the Application Server is reachable via the public internet.
How the PaperCut NG MF Vulnerability Was Discovered
The alarm was raised after a customer reported suspicious network activity to PaperCut’s security response team. Upon investigating the internal logs, PaperCut engineers successfully reproduced the bug and confirmed that remote exploitation was being utilized in the wild.
While a formal CVE (Common Vulnerabilities and Exposures) identifier has not yet been assigned, the technical root cause of this PaperCut NG MF vulnerability is being kept heavily guarded to prevent further weaponization by threat actors.
Indicators of Compromise (IoCs): Are You Hacked?
Security teams must immediately hunt for post-exploitation behavior. The absence of warning signs does not confirm your system is safe, but the presence of the following artifacts is a strong indicator of a breach:

| Artifact Type | What to Look For |
|---|---|
| Process Anomalies | Suspicious child processes originating from pc-app.exe |
| Log Files | Missing, deleted, or unexpectedly truncated server.log files |
| Specific Error 1 | ERROR No suitable driver found for jdbc:no:x |
| Specific Error 2 | ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST |
Immediate Mitigation and Emergency Patching
Because this vulnerability targets internet-facing servers, IT administrators must take aggressive action immediately.
1. Restrict Network Access
PaperCut strongly advises all customers to restrict access to their Application Server using strict firewall rules. Ensure the server is only accessible from trusted internal IP ranges or via a secure VPN. Do this even if you plan to patch later today.
2. Apply the Emergency Build
As verified via the official live bulletin, PaperCut released an emergency patch at 2:10 AM AEST on August 28, 2026. This patch covers the v25 and v26 branches for Windows, Linux, and macOS. Administrators should check the official PaperCut security bulletin directly for download links and the latest patch status.
3. Check Your Public Exposure
Security researchers routinely scan for internet-facing PaperCut servers (commonly running on ports 9191/9192). If you’re unsure whether your Application Server is publicly reachable, use an external port scanner (e.g., Shodan or Censys) from outside your network to confirm โ don’t assume your firewall rules are working as intended.
A History of Targeted Attacks (Ransomware Threat)
The 2023 PaperCut authentication bypass flaw (CVE-2023-27351) was rapidly weaponized by the Clop and LockBit ransomware gangs within days of disclosure, landing it directly in the official CISA Known Exploited Vulnerabilities catalog.
Given that history, security teams should treat this 2026 incident with the same urgency โ attackers are known to move fast once a PaperCut flaw becomes public knowledge. For a broader look at how threat actors leverage such flaws to move laterally, review our guide on Ransomware Infrastructure Defense.
Frequently Asked Questions (FAQ)
Has PaperCut released a patch yet?
Not yet, as of this writing. PaperCut’s official guidance remains to restrict network access to the Application Server immediately. The vendor has stated it is actively working on a fix and will update its bulletin once one is available โ check the official bulletin for the latest status before making changes to your environment.
What is the CVE for the new 2026 PaperCut vulnerability?
As of August 27, 2026, a formal CVE identifier has not yet been assigned to this specific zero-day vulnerability, though it has been confirmed as an active threat by the vendor.
How do I know if my PaperCut server was breached?
Security teams should check for suspicious behavior from the pc-app.exe process and look for specific database errors in the server.log files. However, advanced hackers can wipe logs, so absence of evidence is not evidence of safety.
Verdict
The active exploitation of this PaperCut NG MF vulnerability highlights the critical danger of exposing internal enterprise applications to the public internet. Opportunistic attackers are currently scanning the web for vulnerable instances. Swift patching and immediate network segmentation are non-negotiable for any organization running PaperCut in a production environment.




