The PaperCut NG/MF vulnerability is currently being actively exploited, putting all supported versions of this widely used print management software at risk. PaperCut has confirmed multiple incidents and released emergency patches in response, signalling a significant threat to organisations using these platforms.
Details of the PaperCut NG/MF Vulnerability Exploitation
This critical vulnerability was first identified in late August 2026 when PaperCut’s security team began investigating confirmed incidents involving customer systems. The issue affects every supported version of both PaperCut NG and PaperCut MF, meaning that the specific version deployed does not mitigate exposure. The discovery originated from a university customer whose internal security and forensics teams reported suspicious activity, enabling PaperCut engineers to reproduce the bug and confirm active exploitation in the wild.
As of the latest update, PaperCut has not disclosed the full technical details of the vulnerability. The company has not yet assigned a CVE identifier, reflecting the ongoing nature of the investigation. However, the urgency of the vendor’s response—including the release of same-day emergency builds—strongly suggests a remotely exploitable flaw, particularly targeting servers directly accessible from the internet.
Immediate Timeline and Patch Release
- 27 August 2026: PaperCut is alerted to the vulnerability by a university customer’s security team.
- Early hours of 28 August 2026 (2:10 a.m. AEST): Emergency, out-of-cycle builds are released for v25 and v26 of both NG and MF, covering Windows, Linux and macOS. These are labelled as emergency releases, not standard updates.
- Builds for the older v24 branch are still under development. Customers are urged to upgrade to the latest available version as soon as possible.
PaperCut’s advisory notes that these emergency builds are specifically intended for administrators who cannot immediately isolate their public-facing servers from the internet. The company stresses that public exposure of PaperCut application servers significantly increases the risk of exploitation while a full fix is pending.
Scope of Impact and Attack Mechanisms
Every currently supported version of PaperCut NG and MF is affected, making version numbers irrelevant for risk assessment. The attack path appears to involve remote exploitation of servers exposed to the public internet. PaperCut has not yet detailed the technical root cause, but the patterns observed align with previous exploitation attempts against the platform.
This is not the first time PaperCut has faced such a threat. In 2023, an authentication bypass vulnerability (CVE-2023-27351) was widely exploited by ransomware operators and appeared in CISA’s Known Exploited Vulnerabilities catalogue. This precedent increases the likelihood that opportunistic attackers will swiftly target organisations that have not yet patched or isolated their systems.
Indicators of Compromise and Post-Exploitation Behaviour
PaperCut’s guidance includes several specific indicators that may suggest compromise:
- Unexpected activity by the pc-app.exe process
- Missing or truncated server.log files
- Log entries containing “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST”
It is important to note that the absence of these indicators does not guarantee system safety. PaperCut has stated that additional, validated indicators of compromise will be published as their investigation progresses.
Mitigation Actions and Current Exploitation Status
PaperCut is urging all customers to take immediate action, regardless of whether suspicious activity has been observed. The company’s recommendations include:
- Restricting internet access to PaperCut application servers by allowing only trusted IP addresses, preferably internal networks, using firewall rules or equivalent network access controls.
- Applying the emergency builds provided for v25 and v26 as soon as feasible. Customers on older versions should upgrade at the earliest opportunity.
- Searching for indicators of compromise as outlined above, including examining pc-app.exe activity and server.log file integrity.
The situation remains dynamic, with PaperCut confirming that the vulnerability is being actively abused in the wild. The risk is heightened for publicly accessible servers, and rapid patching or network isolation is crucial. Builds for the v24 branch are forthcoming, and organisations should monitor the official PaperCut security bulletin for updates.
Why This Incident Matters
This event demonstrates a continuing trend of attackers targeting widely deployed business infrastructure software. The fact that all supported versions of PaperCut NG and MF are impacted, combined with confirmed real-world exploitation and the vendor’s urgent response, underscores the criticality of swift action. Any delay in isolating or patching vulnerable servers increases the risk of compromise, data leakage or disruption to print management services.
What Organisations Should Do Now
- Immediately restrict access to PaperCut servers from the public internet.
- Apply the emergency patches for v25 and v26 or upgrade to the latest supported versions.
- Check for the specific compromise indicators listed by PaperCut, even if no suspicious activity is currently visible.
- Monitor PaperCut’s security bulletin for further updates and validated indicators of compromise.
Organisations should prioritise these actions to minimise the risk of exploit while the situation develops and further technical details become available.
Originally reported by cybersecuritynews.com.






