
🛡️ **BREAKING: PaperCut NG/MF Pre-Auth RCE Under Active Exploitation**
Published Friday, August 28, 2026 at 10:56 AM PT BLUF: PaperCut NG and PaperCut MF print management platforms are under active, in-the-wild exploitation via a pre-authentication remote code execution vulnerability. Huntress has independently reproduced the exploit. Organizations running PaperCut must patch immediately and assess compromise risk. Patch details and indicators available from Huntress. DETAILS Affected Products: PaperCut NG and PaperCut MF (specific version ranges not provided in available advisory summary; verify against Huntress guidance) Attack Surface: Pre-authentication RCE — unauthenticated attacker can achieve code execution; no user interaction required Exploitation Status: Active, in-the-wild exploitation confirmed; Huntress ThreatOps team has reproduced the attack chain independently Severity Indicator: Huntress flags this with urgent patching and exposure guidance language — consistent with critical/CVSS 9.0+ Detection: Organizations should assume exploitation attempts have already occurred; forensics on PaperCut server logs and network telemetry are recommended IMPACT ...