
🛡️ **CRITICAL: PaperCut NG/MF Zero-Day Under Active Exploit—All Versions at Risk**
Published Thursday, August 27, 2026 at 10:48 AM PT BLUF PaperCut NG and MF (all currently supported versions) contain an actively exploited unpatched vulnerability with remote exploitation capability. Organizations must immediately restrict internet access to affected servers via firewall and apply emergency patches released 28 August 2026. DETAILS Vulnerability scope: Unspecified flaw affects every currently supported version of PaperCut NG and MF; version number is irrelevant to exposure. Active exploitation confirmed: PaperCut’s security team reproduced the bug and confirmed real-world compromise of at least one university customer (discoverer). CVE status: No CVE identifier assigned as of alert date; technical details remain undisclosed pending investigation. Emergency response: PaperCut released emergency out-of-cycle builds at 2:10 a.m. AEST, 28 August 2026, covering v25 and v26 branches (Windows, Linux, macOS installers). v24 branch build in progress. Attack vector: Presumed remote exploitation path targeting internet-exposed Application Servers. IMPACT ...