Published Friday, August 28, 2026 at 10:56 AM PT

BLUF: PaperCut NG and PaperCut MF print management platforms are under active, in-the-wild exploitation via a pre-authentication remote code execution vulnerability. Huntress has independently reproduced the exploit. Organizations running PaperCut must patch immediately and assess compromise risk. Patch details and indicators available from Huntress.
DETAILS
- Affected Products: PaperCut NG and PaperCut MF (specific version ranges not provided in available advisory summary; verify against Huntress guidance)
- Attack Surface: Pre-authentication RCE — unauthenticated attacker can achieve code execution; no user interaction required
- Exploitation Status: Active, in-the-wild exploitation confirmed; Huntress ThreatOps team has reproduced the attack chain independently
- Severity Indicator: Huntress flags this with urgent patching and exposure guidance language — consistent with critical/CVSS 9.0+
- Detection: Organizations should assume exploitation attempts have already occurred; forensics on PaperCut server logs and network telemetry are recommended
IMPACT
- Scope: Any organization running unpatched PaperCut NG or MF instances reachable from the internet or untrusted networks
- Risk: Complete server compromise — attacker gains unauthenticated code execution with application privileges, enabling data theft (print job metadata, credentials, user documents), lateral movement, persistence, and destructive operations
- Exposure Window: Unknown when vulnerability was introduced or exploitation began; assume exposure is ongoing until patching is confirmed
RECOMMENDED ACTIONS
- Immediate (Next 4 Hours): Identify all PaperCut NG/MF instances in your environment and check version against patch guidance from Huntress; prioritize internet-facing or DMZ instances
- Urgent (Today): Apply patches from PaperCut/Huntress advisory; if patches are not yet available, implement network segmentation to restrict access to PaperCut servers (firewall rules, VPN requirement)
- Forensics: Check PaperCut application logs, web server access logs (if applicable), and network SIEM for exploitation indicators; contact Huntress or your MDR for IOCs
- Follow-On: Once patched, scan for persistence indicators (unexpected accounts, scheduled tasks, web shells in print directories)
SOURCES
Huntress MDR / ThreatOps — PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE (published alert tracking in-the-wild campaign; critical vulnerabilities guidance available via Huntress portal)
Note: This alert is synthesized from Huntress advisory summary; specific CVE designation, affected version ranges, and detailed patch links should be retrieved directly from the Huntress platform or PaperCut security bulletins.
Recent high-severity events at publish time:

