• News/
  • bleepingcomputer-20260827163153

PaperCut warns of NG, MF flaw exploited in zero-day attacks

BleepingComputer
·
Lawrence Abrams
·
Published Aug 27, 2026
·
Updated

PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses. "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF," reads an urgent security advisory published Thursday. "We are aware of confirmed customer incidents and are treating this matter with the highest priority." PaperCut says the vulnerability affects all versions of PaperCut NG and MF, but has not shared details about the flaw or how it is being exploited. The company says its security team reproduced the vulnerability using information provided by a University customer. PaperCut has now released emergency patches for customers with public-facing PaperCut NG/MF servers. "This is an emergency patch for customers with public-facing PaperCut NG/MF servers who are unable to take other mitigating action," reads the advisory. The company continues to warn customers whose Application Servers are exposed to the Internet to use firewall rules or network access controls to restrict their web interfaces to trusted IP addresses. PaperCut also shared indicators of compromise that could indicate whether a server has been c...

Read full article

Affected Software

2 affected components
PaperCut Software PaperCut NG
PaperCut Software PaperCut MF

Frequently Asked Questions

1

Which PaperCut deployments are affected?

PaperCut says the vulnerability affects all versions of PaperCut NG and PaperCut MF. It specifically urges organizations with Internet-exposed PaperCut Application Servers to take immediate action.

2

What mitigation does PaperCut recommend for Internet-exposed servers?

Organizations should immediately restrict access to PaperCut web interfaces to trusted IP addresses. PaperCut has also released emergency patches for customers with public-facing NG/MF servers that cannot take other mitigating action.

3

Is exploitation confirmed?

Yes. PaperCut says it is aware of confirmed customer incidents and is investigating active exploitation. The company has not disclosed technical details of the vulnerability or the exploitation method.

4

How was the vulnerability validated?

PaperCut says its security team reproduced the vulnerability using information supplied by a University customer. The company is treating the issue as a highest-priority matter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203