- Active Exploitation Warning: PaperCut has confirmed a zero-day vulnerability in NG and MF software allowing unauthenticated remote Java code execution.
- Emergency Remediation: Priority patches are available for versions 25 and 26, while administrators are advised to restrict public internet access to Application Server interfaces.
Active Zero-Day Attacks Target Print Management
PaperCut issued an urgent security advisory on August 27, 2026, warning of active zero-day exploitation affecting PaperCut NG and PaperCut MF. The software, which is widely used for enterprise print management, faces a vulnerability that allows unauthenticated attackers to gain remote control over the software’s trusted configuration. Once access is gained, threat actors can execute arbitrary Java code. This incident follows a broader trend of vulnerabilities targeting network infrastructure, such as the unpatched Calix router flaw that recently permitted remote NAT bypass.
The flaw impacts all versions of PaperCut NG and MF. PaperCut NG is primarily used to manage print processes from servers, while PaperCut MF integrates directly with multi-function copier touchscreens. The primary target in these attacks is the Application Server, which serves as the central management brain for the entire printing environment. Threat researchers at Huntress confirmed that a complete remote code execution chain is possible against stock installations of the software, similar to the risks seen in the critical Avada WordPress theme flaw regarding remote execution capabilities.
According to the Huntress technical analysis, observed post-exploitation activity include the execution of base64-encoded commands. Attackers have been seen using “whoami” and “ver” to identify user accounts and operating system versions on compromised hosts.
Indicators of Compromise and Security Logs
Specific Indicators of Compromise (IoCs) have been identified to help organizations detect potential breaches. Security teams should look for suspicious activity originating from the “pc-app.exe” process. Furthermore, missing or truncated server.log files may suggest that an attacker is attempting to hide their tracks. Technical evidence of a compromise may also appear in log entries as the string: “ERROR No suitable driver found for jdbc:no:x”.
When investigating lateral movement or persistence, administrators should also review named pipe security and Windows IPC mechanisms for unauthorized connections. Information provided by a university customer and their incident response team was instrumental in allowing PaperCut to reproduce the vulnerability and identify these specific behavioral markers.
Emergency Patching and Mitigation Steps
As of late August 2026, a formal CVE identifier and specific CVSS score for this new zero-day had not been publicly finalized in initial advisories. However, the BleepingComputer report highlights that emergency builds have been prioritized. Confirmed emergency builds include PaperCut NG version 25.0.12.76497 and PaperCut MF version 25.0.12.76496 for Windows. Emergency patches for version 24 of the software were still in development at the time of the initial August warning.
PaperCut recommends immediately restricting public internet access to Application Server web interfaces via firewall rules or IP whitelisting. This mitigation is vital because the Application Server is the focus of the current exploit chain. Historical data suggests that PaperCut vulnerabilities are high-value targets; in 2023, a similar flaw known as CVE-2023-27350 was utilized by ransomware groups including Clop and LockBit. Detailed technical steps and updates are available through the PaperCut official security advisory.
