Menu
BREAKING NEWS

PaperCut NG/MF Vulnerability Actively Exploited: Emergency Patch Released

Uday Patil Aug 27, 2026 5 min read 16 views
PaperCut NG/MF Vulnerability Actively Exploited: Emergency Patch Released

Live Situation โ€” Last checked: August 27, 2026 (Patch Now Available)

This is a fast-developing story. A critical zero-day PaperCut NG MF vulnerability is being actively exploited in the wild. While no formal CVE is assigned yet, PaperCut has just released an emergency patch as of 2:10 AM AEST (Aug 28). We are monitoring the official bulletin and will update this article as new IOCs are confirmed.

By Uday Patil, Cybersecurity Analyst | Last Updated: August 27, 2026


PaperCut has confirmed that cybercriminals are actively abusing an undisclosed vulnerability in its widely deployed print management solutions. The threat is severe enough that the Australian vendor rushed out an emergency patch just hours after its initial warning.

PaperCut software is deployed across more than 70,000 organizations and 100 million users worldwide, spanning schools, universities, government offices, and enterprises โ€” making this one of the most widely-deployed print management platforms globally.

PaperCut NG MF vulnerability: Illustration of a hacker exploiting a print management server
Cybercriminals are actively exploiting print management servers exposed to the public internet.

According to the official security response team, the flaw impacts every currently supported version of the software. Whether you are running older legacy builds or the latest update, your system is exposed if the Application Server is reachable via the public internet.

How the PaperCut NG MF Vulnerability Was Discovered

The alarm was raised after a customer reported suspicious network activity to PaperCut’s security response team. Upon investigating the internal logs, PaperCut engineers successfully reproduced the bug and confirmed that remote exploitation was being utilized in the wild.

While a formal CVE (Common Vulnerabilities and Exposures) identifier has not yet been assigned, the technical root cause of this PaperCut NG MF vulnerability is being kept heavily guarded to prevent further weaponization by threat actors.

Indicators of Compromise (IoCs): Are You Hacked?

Security teams must immediately hunt for post-exploitation behavior. The absence of warning signs does not confirm your system is safe, but the presence of the following artifacts is a strong indicator of a breach:

Diagram showing 4 signs of compromise for the PaperCut vulnerability including missing log files and process anomalies
Artifact TypeWhat to Look For
Process AnomaliesSuspicious child processes originating from pc-app.exe
Log FilesMissing, deleted, or unexpectedly truncated server.log files
Specific Error 1ERROR No suitable driver found for jdbc:no:x
Specific Error 2ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Immediate Mitigation and Emergency Patching

Because this vulnerability targets internet-facing servers, IT administrators must take aggressive action immediately.

1. Restrict Network Access

PaperCut strongly advises all customers to restrict access to their Application Server using strict firewall rules. Ensure the server is only accessible from trusted internal IP ranges or via a secure VPN. Do this even if you plan to patch later today.

2. Apply the Emergency Build

As verified via the official live bulletin, PaperCut released an emergency patch at 2:10 AM AEST on August 28, 2026. This patch covers the v25 and v26 branches for Windows, Linux, and macOS. Administrators should check the official PaperCut security bulletin directly for download links and the latest patch status.

3. Check Your Public Exposure

Security researchers routinely scan for internet-facing PaperCut servers (commonly running on ports 9191/9192). If you’re unsure whether your Application Server is publicly reachable, use an external port scanner (e.g., Shodan or Censys) from outside your network to confirm โ€” don’t assume your firewall rules are working as intended.

A History of Targeted Attacks (Ransomware Threat)

The 2023 PaperCut authentication bypass flaw (CVE-2023-27351) was rapidly weaponized by the Clop and LockBit ransomware gangs within days of disclosure, landing it directly in the official CISA Known Exploited Vulnerabilities catalog.

Given that history, security teams should treat this 2026 incident with the same urgency โ€” attackers are known to move fast once a PaperCut flaw becomes public knowledge. For a broader look at how threat actors leverage such flaws to move laterally, review our guide on Ransomware Infrastructure Defense.

Frequently Asked Questions (FAQ)

Has PaperCut released a patch yet?

Not yet, as of this writing. PaperCut’s official guidance remains to restrict network access to the Application Server immediately. The vendor has stated it is actively working on a fix and will update its bulletin once one is available โ€” check the official bulletin for the latest status before making changes to your environment.

What is the CVE for the new 2026 PaperCut vulnerability?

As of August 27, 2026, a formal CVE identifier has not yet been assigned to this specific zero-day vulnerability, though it has been confirmed as an active threat by the vendor.

How do I know if my PaperCut server was breached?

Security teams should check for suspicious behavior from the pc-app.exe process and look for specific database errors in the server.log files. However, advanced hackers can wipe logs, so absence of evidence is not evidence of safety.

Verdict

The active exploitation of this PaperCut NG MF vulnerability highlights the critical danger of exposing internal enterprise applications to the public internet. Opportunistic attackers are currently scanning the web for vulnerable instances. Swift patching and immediate network segmentation are non-negotiable for any organization running PaperCut in a production environment.

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers and security teams worldwide with rapid alerts, remediation scripts, and practical guidance to stay ahead of the evolving threat landscape.