← Back to Feed
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
August 28, 2026 · The Hacker News · Severity: CRITICAL
PaperCut disclosed a zero-day vulnerability in its NG and MF print management software that is being actively exploited. The company released emergency patches for versions 25 and 26 and urged customers to restrict web interface access to trusted IP addresses. Indicators of compromise include suspicious activity from pc-app.exe and missing server.log files.
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An investigation into the incident is ongoing. The following indicators of compromise have been shared so far - Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from "pc-app.exe" Missing, unexpectedly truncated, or deleted PaperCut server.log files The presence of the below entries in "server.log" - ERROR No suitable driver found for jdbc:no:x ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST There are currently no details about the flaw, how it is being exploited, or who is behind the efforts. Users who have PaperCut NG/MF Application Server exposed to the internet are advised to immediately restrict access to trusted IP addresses. "Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut servers web interfaces cannot be reached from untrusted internet addresses," PaperCut said. "Take this action now, even if you have not observed suspicious activity." In 2023, a critical flaw in PaperCut MF and NG ( CVE-2023-27350 , CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware. (This is a developing story. Please check back for more details.) Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- PaperCut NG and MF all versions are under active zero-day exploitation by attackers.
- Emergency patches for versions 25 and 26 have been released to address the flaw.
- Organizations must immediately restrict PaperCut web interfaces to trusted IP addresses.