Published Friday, August 28, 2026 at 04:54 AM PT

BLUF: PaperCut Software has issued an emergency security update to address a critical zero-day vulnerability actively exploited in the wild affecting all versions of PaperCut NG and MF print management systems. Organizations running these products must patch immediately. CVE identifier pending.
DETAILS
- Active exploitation confirmed. As of August 27, 2026, PaperCut is aware of zero-day attacks leveraging this vulnerability in production environments.
- All NG and MF versions in scope. The flaw affects the complete product line; no version range exclusion has been announced.
- CVE not yet assigned. PaperCut published the advisory and emergency patch before CVE assignment, indicating coordinated speed-to-patch.
- Code execution implied. Security research references indicate the flaw exposes admin access and enables arbitrary code execution on affected systems.
- No technical details released. PaperCut’s advisory does not disclose the attack vector or vulnerability mechanism to limit exposure during active exploitation.
IMPACT
Any organization running PaperCut NG or MF for print management, accounting, or document workflow is vulnerable. This includes enterprise deployments integrated with authentication backends and document pipelines. Successful exploitation grants attacker code execution within the print system, enabling:
- Access to administrative functions
- Lateral movement into document repositories and user data
- Potential compromise of billing/accounting data
- Supply chain impact if PaperCut is integral to customer-facing services
RECOMMENDED ACTIONS
- Immediate: Review your infrastructure for PaperCut NG or MF deployments and confirm which versions are running.
- Within 24 hours: Download and install PaperCut’s emergency patch. Vendor advisories confirm it is available now.
- Post-patch: Restart affected PaperCut services and validate through health checks.
- Monitor for compromise: Review access logs and authentication events on PaperCut systems dating back 7–14 days for signs of exploitation.
- Watch for CVE publication: Once the CVE is assigned, cross-reference your SIEM/vulnerability scanner to flag any historical log entries.
Organizations without immediate patching capability should isolate PaperCut systems from untrusted networks pending remediation.
SOURCES
- Rapid7 (published August 27, 2026)
- SecurityWeek, SecurityAffairs, The Hacker News, BleepingComputer (corroborating active exploitation and scope)
- PaperCut Software official advisory
Recent high-severity events at publish time:

