Skip to main content
cybersecurity

PaperCut NG/MF Under Active Attack: Emergency Patch Released for Zero-Day Vulnerability

PaperCut has confirmed active exploitation of an undisclosed vulnerability affecting all PaperCut NG and MF versions. Organisations with internet-exposed servers should restrict access immediately and apply the emergency patch where available.

Xcademia Team

Xcademia Research Team

Aug 28, 20265 min read10 views
Share:
PaperCut NG/MF Under Active Attack: Emergency Patch Released for Zero-Day Vulnerability

PaperCut Software has issued an urgent security advisory after confirming that attackers are actively exploiting a vulnerability in its PaperCut NG and PaperCut MF print management products.

The company says it is aware of confirmed customer incidents and is treating the investigation as a security emergency. The vulnerability has not yet been publicly assigned a CVE identifier, and PaperCut has not disclosed its technical root cause or exploitation method.

As of 28 August 2026, PaperCut has released an emergency patch for NG and MF versions 25 and 26. The company says the emergency release is intended for customers with publicly exposed PaperCut servers who cannot immediately apply other mitigation measures.

Internet-facing PaperCut servers are the immediate concern

PaperCut's most urgent instruction is aimed at organisations whose PaperCut NG/MF Application Server can be reached from the public internet.

Administrators should immediately restrict access to the server's web interfaces so they can only be reached from trusted IP addresses. PaperCut recommends using firewall rules, network access controls or equivalent protections.

The vendor says this action should be taken even if an organisation has not identified suspicious activity.

This is particularly important because the vulnerability is already being exploited. Waiting for additional technical details before applying basic network restrictions could leave an exposed Application Server unnecessarily reachable by attackers.

info-1


Emergency patches released for versions 25 and 26

PaperCut has now published emergency patch packages for PaperCut NG and PaperCut MF versions 25 and 26.

The available packages cover Windows, Linux and macOS installations. PaperCut also provides SHA-256 checksums for the downloadable packages so administrators can verify the integrity of the files before deployment.

The company describes these packages as an emergency patch rather than a normal product release. They were issued outside PaperCut's usual release process for customers who operate public-facing servers and cannot rely solely on other mitigations.

PaperCut has also confirmed that builds for version 24 are still in progress and recommends upgrading to the latest available version whenever possible.

What organisations should do now

Security and infrastructure teams managing PaperCut NG or MF should treat the advisory as an active incident rather than a routine software update.

The immediate response should include:

  1. Identify all PaperCut NG/MF Application Servers.

  2. Determine whether any Application Server is accessible from the public internet.

  3. Restrict public access immediately using firewall rules or network access controls.

  4. Apply the emergency patch if running version 25 or 26 and the server requires the emergency release.

  5. Review logs and security monitoring systems for signs of suspicious activity.

  6. Investigate potentially compromised systems rather than assuming that patching alone removes an existing compromise.

  7. Continue monitoring PaperCut's security advisory for additional indicators and remediation guidance.

PaperCut has not provided enough information to determine the complete attack chain, so organisations should avoid treating the absence of a known indicator as proof that a server is unaffected.

info-2


Indicators of compromise

PaperCut has published several indicators that administrators can use during an initial investigation.

Security monitoring tools may report suspicious activity involving the PaperCut Application Server. PaperCut specifically highlights potentially suspicious post-exploitation activity involving the legitimate pc-app.exe process.

Administrators should also investigate situations where PaperCut's server.log files are:

  • Missing

  • Unexpectedly truncated

  • Deleted

The company has also identified two specific log entries that may indicate suspicious activity:

ERROR No suitable driver found for jdbc:no:x

ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

However, PaperCut explicitly warns that not finding these indicators does not confirm that a system has not been compromised.

info-3


PaperCut reproduced the vulnerability

The investigation began after PaperCut received information from a university customer's security and digital forensics and incident response teams.

According to PaperCut, the information allowed its security emergency response team to reproduce the vulnerability in the PaperCut NG and MF code. Its emergency engineering team then worked on developing and validating an appropriate fix.

PaperCut has not disclosed the vulnerability's underlying technical details at this stage.

Additional details were not disclosed in the announcement.

That means organisations should not assume whether the flaw involves authentication, remote code execution, privilege escalation, SQL injection or another vulnerability class unless PaperCut officially confirms it.

A new risk for organisations running self-hosted print infrastructure

PaperCut NG and MF are used to manage printing environments, including deployments where a central Application Server controls or coordinates print-related services.

That makes the Application Server an important infrastructure component. If its administrative or web interfaces are unnecessarily exposed to the internet, a vulnerability in the server can become a direct security concern for the organisation operating it.

The current PaperCut response therefore follows a familiar security principle: reduce external exposure first, then apply the available remediation and investigate for compromise.

For enterprises, schools, universities and other organisations using self-hosted print management, the incident is also a reminder that security controls need to cover infrastructure that may not traditionally be considered a high-priority attack surface.

External database users should review the patch impact

PaperCut has highlighted an additional consideration for customers using Card/ID number lookups against an external database.

In the patched builds, SQL queries used by this feature can no longer contain EXEC, EXECUTE or CALL statements. Organisations relying on those statements should review their configuration before deploying the emergency patch.

The restriction is directly related to the emergency security changes, so administrators should test affected configurations as part of the upgrade process.

The company did not provide specific information about this area's wider operational impact.

Why this incident matters

The most important aspect of this advisory is not the lack of a CVE number or public technical analysis. It is the combination of three factors:

  • PaperCut has confirmed active exploitation.

  • Customer incidents have been confirmed.

  • An emergency patch has been released for versions 25 and 26.

This means organisations should not wait for a complete technical disclosure before taking defensive action.

The development also highlights a broader industry shift toward treating internet-exposed application servers as high-priority security assets, regardless of whether they sit inside traditional security categories such as databases, identity systems or endpoint infrastructure.

For enterprises, this could mean reviewing whether management interfaces for print, monitoring, administration and other operational systems genuinely need direct internet exposure.

What happens next

PaperCut says its investigation remains ongoing. The company expects to update its advisory as verified information becomes available, including additional indicators of compromise and remediation guidance.

At present, the vendor has not publicly disclosed the vulnerability's CVE identifier, severity rating, CVSS score, exploitation technique or threat actor attribution.

Additional details were not disclosed in the announcement.

Organisations should therefore base their immediate response on the information currently verified by PaperCut: restrict internet access, deploy the applicable emergency patch, investigate for signs of compromise and monitor the vendor's advisory for further updates.

Security takeaway

The PaperCut NG/MF incident demonstrates why internet exposure can turn an otherwise specialised enterprise application into a security priority.

For organisations running affected PaperCut deployments, the safest immediate approach is straightforward: remove unnecessary public exposure, apply the available emergency remediation and investigate before assuming the environment is clean.

PaperCut's advisory should remain the primary source for subsequent technical updates and remediation instructions.

#PaperCut#Cybersecurity#ZeroDay#Vulnerability#PrintSecurity#SecurityAdvisory#IncidentResponse#EnterpriseSecurity

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, with optional Career+ support.