Published Friday, September 11, 2026 at 05:09 AM PT

<strong>BREAKING โ€” DEVELOPING: PaperCut Actively Exploited; Multiple Zero-Days, Rapid Patch Cycle</strong>

BLUF: PaperCut Software has issued emergency patches for at least two actively exploited zero-day vulnerabilities affecting print management systems. Attackers are chaining the flaws to achieve unauthenticated code execution. As of the latest update, ~47% of PaperCut servers remain unpatched. Organizations running PaperCut NG or MF versions must patch immediately.

DETAILS:

  • Active exploitation confirmed. Two zero-day flaws are being chained together in live attacks to execute code without authentication.
  • Patch cycle accelerated. PaperCut has released multiple emergency patches in rapid succession, indicating severity and ongoing discovery.
  • High exposure. Attackers are actively probing PaperCut servers in the wild; widespread reconnaissance suggests credential harvest or lateral movement prep.
  • Scope: NG/MF versions. PaperCut NG and MF product lines confirmed affected; all versions mentioned as vulnerable in open sources.
  • Patch adoption lag. Approximately 47% of known PaperCut installations remain unpatched despite emergency release, indicating deployment friction or visibility gaps.

IMPACT:

  • Who: Organizations running PaperCut print/document management systems (government, enterprise, education sectors heavily affected).
  • What: Unauthenticated remote code execution with presumed system-level privileges; likely leads to credential theft, lateral movement, or supply-chain staging.
  • When: Exploitation ongoing; probing is active.

RECOMMENDED ACTIONS:

  • Immediately apply the latest PaperCut emergency patch to all NG/MF instances.
  • If patching is delayed, isolate PaperCut systems from untrusted networks and implement strict firewall ingress controls.
  • Check logs for reconnaissance attempts or exploitation signatures (HTTP requests to unauthenticated endpoints).
  • Monitor for lateral movement from compromised print servers to credential stores or sensitive file shares.

SOURCES:

  • The Hacker News (headline-level confirmation of chained exploitation, code execution without auth)
  • BleepingComputer (second emergency patch confirmation)
  • SecurityWeek (zero-day active attack, patch velocity)
  • SecurityAffairs (47% unpatched metric, active server probing)

STATUS: Details on specific CVE identifiers, exact affected versions, and exploitation vectors remain incomplete. Further detail expected as patches stabilize and post-mortems emerge.


Recent high-severity events at publish time:

Recent high-severity events