Published Friday, September 11, 2026 at 05:09 AM PT

BLUF: PaperCut Software has issued emergency patches for at least two actively exploited zero-day vulnerabilities affecting print management systems. Attackers are chaining the flaws to achieve unauthenticated code execution. As of the latest update, ~47% of PaperCut servers remain unpatched. Organizations running PaperCut NG or MF versions must patch immediately.
DETAILS:
- Active exploitation confirmed. Two zero-day flaws are being chained together in live attacks to execute code without authentication.
- Patch cycle accelerated. PaperCut has released multiple emergency patches in rapid succession, indicating severity and ongoing discovery.
- High exposure. Attackers are actively probing PaperCut servers in the wild; widespread reconnaissance suggests credential harvest or lateral movement prep.
- Scope: NG/MF versions. PaperCut NG and MF product lines confirmed affected; all versions mentioned as vulnerable in open sources.
- Patch adoption lag. Approximately 47% of known PaperCut installations remain unpatched despite emergency release, indicating deployment friction or visibility gaps.
IMPACT:
- Who: Organizations running PaperCut print/document management systems (government, enterprise, education sectors heavily affected).
- What: Unauthenticated remote code execution with presumed system-level privileges; likely leads to credential theft, lateral movement, or supply-chain staging.
- When: Exploitation ongoing; probing is active.
RECOMMENDED ACTIONS:
- Immediately apply the latest PaperCut emergency patch to all NG/MF instances.
- If patching is delayed, isolate PaperCut systems from untrusted networks and implement strict firewall ingress controls.
- Check logs for reconnaissance attempts or exploitation signatures (HTTP requests to unauthenticated endpoints).
- Monitor for lateral movement from compromised print servers to credential stores or sensitive file shares.
SOURCES:
- The Hacker News (headline-level confirmation of chained exploitation, code execution without auth)
- BleepingComputer (second emergency patch confirmation)
- SecurityWeek (zero-day active attack, patch velocity)
- SecurityAffairs (47% unpatched metric, active server probing)
STATUS: Details on specific CVE identifiers, exact affected versions, and exploitation vectors remain incomplete. Further detail expected as patches stabilize and post-mortems emerge.
Recent high-severity events at publish time:

