PaperCut NG and MF Vulnerability Is Being Actively Exploited
PaperCut confirmed incidents affecting customers and the active exploitation of an as-yet-unspecified flaw in PaperCut NG and PaperCut MF. The risk affects all versions.

PaperCut NG and MF are facing an as-yet-unspecified vulnerability that is being actively exploited, according to the vendor. On August 27, 2026, the company confirmed incidents affecting customers and urged administrators to immediately restrict access to publicly accessible Application Servers.
The warning applies to all versions of both PaperCut NG and PaperCut MF. PaperCut has not yet published a CVE identifier, the flaw’s technical mechanism, or its severity. The zero-day designation therefore describes a situation involving an actively exploited, as-yet-unspecified flaw; it is not a publicly assigned technical classification from the vendor.
PaperCut NG and MF: Restrict Access Immediately
According to PaperCut, administrators of servers accessible from the internet should immediately restrict access to the web interfaces to trusted IP addresses only. The recommendation applies to Application Servers that are publicly accessible and may be directly exposed to the ongoing exploitation.
The vendor has released emergency fixes for the PaperCut NG/MF v25 and v26 branches. They are intended for customers with publicly accessible servers who cannot use other mitigating measures. For the v24 branch, the relevant builds were still in development at the time of the security advisory’s latest update.
Organizations using v24 should therefore monitor the vendor’s build availability while also reducing the server’s exposure as recommended. The warning does not apply only to a specific unsupported or older branch, but to all versions of both products.
What to Check for Suspected Compromise
PaperCut listed several possible indicators of compromise. These include suspicious activity involving the pc-app.exe process, missing or unexpectedly truncated server.log files, and two specific error messages in the log that the vendor identifies in its security bulletin.
However, the absence of these traces does not rule out compromise. Administrators should therefore not consider a system safe solely because they did not find the listed indicators.
Undisclosed Attack Details
It has not been publicly confirmed who is carrying out the attacks, how many organizations they have affected, or what follow-on activities the attackers perform after gaining access. PaperCut has likewise not disclosed whether data theft occurred in the confirmed incidents.
Administrators should monitor further announcements from the vendor, including the availability of the proper fix and a build for v24. Technical details of the flaw, a possible CVE assignment, and more precise indicators of compromise may also be important if the vendor publishes them.
Sources
- PaperCut — URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) – Confirms active exploitation and customer incidents, the scope covering all versions, recommended access restrictions, indicators of compromise, and emergency fixes for v25 and v26.
- BleepingComputer — PaperCut warns of NG, MF flaw exploited in zero-day attacks – Independently summarizes PaperCut’s warning and its recommendations for publicly accessible Application Servers.
Verified and updated: 08/27/2026 20:31



