Published Tuesday, September 01, 2026 at 05:07 AM PT

<strong>PAPERCUT ZERO-DAYS EXPLOITED FOR DATA THEFT — PATCHES RELEASED</strong>

BLUF: PaperCut has released patches for recently disclosed zero-day vulnerabilities affecting NG (Next Generation) and MF (Multi-Functional) product lines that are actively being exploited in data theft campaigns. Organizations running unpatched PaperCut environments should treat this as critical—apply patches immediately if you operate print management systems based on PaperCut.

DETAILS:

  • PaperCut zero-day flaws (NG and MF variants identified) have entered active exploitation in the wild for data theft operations
  • Vulnerabilities were zero-day at discovery, meaning no patch existed when attacks began
  • PaperCut has released emergency security patches; a second emergency patch followed the initial release, indicating either additional flaws or wider-than-expected impact
  • Attack campaigns explicitly target data exfiltration—not just system compromise or availability disruption
  • Multiple independent security outlets (BleepingComputer, news4hackers) confirm the threat is real and ongoing

IMPACT:

  • Affected: Organizations running unpatched PaperCut NG or MF print management systems
  • Scope: These products are common in enterprise print environments, universities, healthcare, and managed service provider networks
  • Risk: Attackers can exploit these flaws to move laterally into corporate networks, steal documents, and exfiltrate sensitive data (credentials, intellectual property, personal information)
  • Severity: Active exploitation by threat actors—not theoretical or isolated to proof-of-concept

RECOMMENDED ACTIONS:

  1. Immediate: Identify all PaperCut NG/MF instances in your environment (including managed/hosted variants)
  2. Today: Check PaperCut’s security advisory for current patch versions; verify if your instances are running patched code
  3. This week: Apply all available PaperCut security patches to NG/MF systems (test in non-production first if possible, but prioritize speed—these are being actively exploited)
  4. Monitor: Check PaperCut logs for unusual access patterns, API calls, or document pulls; review network traffic to/from print systems for data exfiltration indicators
  5. Contingency: If patching is delayed, consider isolating print systems from sensitive networks or restricting their access until patches are deployed

SOURCES:

  • BleepingComputer (primary reporting on patched zero-days used in data theft)
  • BleepingComputer (PaperCut NG/MF zero-day warning and second emergency patch advisory)
  • news4hackers (PaperCut zero-day exploit correlation to data theft incidents)

This alert is based on headline-level reporting from security media. Patch details and technical indicators of compromise are not included in available material.


Recent high-severity events at publish time:

Recent high-severity events