PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
- ID
- 18944
- Status
- summarized
- Published
- 28 Aug 2026, 4:25 PM
- Fetched
- 28 Aug 2026, 5:26 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 28 Aug 2026, 5:27 PM
- Tags
- Audience
- developersvibe_coders
What happened
PaperCut has confirmed active zero-day exploitation affecting all versions of PaperCut NG and PaperCut MF print management software, with emergency patches released for v25 and v26. The company shared specific IOCs including suspicious post-exploitation activity from 'pc-app.exe', missing or truncated server.log files, and particular JDBC/database error entries in logs, but has not yet disclosed the flaw details or threat actors involved.
Why it matters
If your organization runs PaperCut NG or MF with the Application Server exposed to the internet, restrict access to trusted IPs via firewall rules immediately—even before patching—and check for the three published IOC signatures in server.log and endpoint monitoring. This mirrors the 2023 CVE-2023-27350 (CVSS 9.8) exploitation by Russian threat actors and Lace Tempest delivering Cl0p and LockBit ransomware, so unpatched internet-facing servers are high-value targets.
Discussion angle
How many organizations still expose print management servers directly to the internet, and whether the recurring PaperCut zero-day pattern (2023 and now 2026) suggests the product's architecture is fundamentally difficult to secure—or whether this is purely a patch-hygiene problem.