Published Thursday, August 27, 2026 at 10:48 AM PT

BLUF
PaperCut NG and MF (all currently supported versions) contain an actively exploited unpatched vulnerability with remote exploitation capability. Organizations must immediately restrict internet access to affected servers via firewall and apply emergency patches released 28 August 2026.
DETAILS
- Vulnerability scope: Unspecified flaw affects every currently supported version of PaperCut NG and MF; version number is irrelevant to exposure.
- Active exploitation confirmed: PaperCut’s security team reproduced the bug and confirmed real-world compromise of at least one university customer (discoverer).
- CVE status: No CVE identifier assigned as of alert date; technical details remain undisclosed pending investigation.
- Emergency response: PaperCut released emergency out-of-cycle builds at 2:10 a.m. AEST, 28 August 2026, covering v25 and v26 branches (Windows, Linux, macOS installers). v24 branch build in progress.
- Attack vector: Presumed remote exploitation path targeting internet-exposed Application Servers.
IMPACT
All organizations running PaperCut NG or MF in production are at risk. Enterprises, universities, government agencies, and managed print service providers using internet-facing Application Servers face immediate compromise risk. Print management systems control access to networked devices, document workflows, and potentially organizational billing systems.
RECOMMENDED ACTIONS
Immediate (within hours):
- If PaperCut Application Server is reachable from the public internet, immediately restrict access via firewall rules or network access controls to trusted internal IPs only—do not wait for patches or for evidence of compromise.
- Begin log hunting for indicators of compromise:
- Suspicious behavior originating from
pc-app.exeprocess - Missing or unexpectedly truncated
server.logfiles - Log entries reading
ERROR No suitable driver found for jdbc:no:xorERROR DatabaseUtils Database error looking up cardID: VALUES CAST - Note: Absence of these artifacts does NOT confirm a system is safe; keep monitoring.
- Suspicious behavior originating from
Short-term (within 24–48 hours): 3. Upgrade to emergency patches for v25 or v26 branches (both released 28 August). 4. For v24 branch systems, patch as soon as build becomes available; upgrade to v25/v26 if v24 build is delayed. 5. Coordinate with PaperCut support for validated indicators of compromise as investigation matures.
Historical context:
A similar PaperCut flaw (CVE-2023-27351, authentication bypass) was exploited by ransomware groups in 2023 and reappeared on CISA’s Known Exploited Vulnerabilities list in 2026, suggesting opportunistic attackers will rapidly scan for exposed instances of this new flaw.
SOURCES
- PaperCut official security advisory (28 August 2026)
- Cybersecurity News / CybersecurityNews.com (27 August 2026)
- news4hackers feed aggregation
Recent high-severity events at publish time:

