VYPR
advisoryPublished Aug 27, 2026· Updated Aug 31, 2026· 5 sources

PaperCut NG/MF Vulnerability Actively Exploited, Vendor Warns

PaperCut Software has issued a critical warning about an unspecified vulnerability in its PaperCut NG and PaperCut MF print management solutions, confirming active exploitation and customer incidents.

PaperCut Software has alerted its users to an unspecified vulnerability affecting its widely deployed PaperCut NG and PaperCut MF print management solutions, confirming that the flaw is currently being actively exploited in the wild. The company stated, "We are aware of confirmed customer incidents and are treating this matter with the highest priority." This advisory comes as a significant concern for organizations relying on PaperCut for managing their printing infrastructure.

PaperCut NG is a popular print management software designed for environments such as offices, schools, and other institutions. Its counterpart, PaperCut MF (Multi-Function), is an enhanced version that integrates directly with all-in-one office copier machines, enabling management of print, copy, scan, and fax functions directly from the device's touchscreen. These solutions are embedded in workflows across numerous major brands of office equipment, making them a critical component of many organizations' operational security.

The security bulletin released by PaperCut strongly suggests a remotely exploitable nature for this vulnerability. The vendor explicitly advised, "If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses)." The Application Server acts as the central control unit for both PaperCut NG and MF, typically deployed as a single instance within an organization.

While PaperCut Software is still actively investigating the full scope and technical details of the exploit, they have committed to publishing specific indicators of compromise (IOCs) once they are identified. In the interim, customers are urged to remain vigilant for general signs of compromise. These include alerts from security tools pointing to suspicious post-exploitation activity on the PaperCut Application Server (specifically involving pc-app.exe), unexpected modifications or deletions of server.log files, or the presence of specific error messages within the logs such as "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST."

Even in the absence of these specific indicators, PaperCut's advisory emphasizes the critical need to restrict external access to the Application Server. The vendor recommends implementing firewall rules, network access controls, or equivalent security measures to ensure that the web interfaces of the PaperCut server are not reachable from untrusted internet addresses. This proactive step is crucial for mitigating the risk of exploitation while the investigation continues.

This incident echoes past security concerns surrounding PaperCut software. In 2023, threat actors associated with the Clop and LockBit ransomware operations successfully exploited two known vulnerabilities, CVE-2023-27350 and CVE-2023-27351. These flaws allowed for remote code execution and information disclosure, highlighting a recurring pattern of exploitation targeting the platform's security.

The active exploitation of this new, unspecified vulnerability underscores the persistent threat landscape faced by organizations relying on print management solutions. The widespread adoption of PaperCut NG and MF in educational and corporate environments means that a successful exploit could have significant implications for data security and operational continuity. The vendor's swift warning and guidance on restricting access aim to provide immediate mitigation steps for affected customers.

The new article provides critical details on the ongoing exploitation of the PaperCut NG/MF vulnerability, noting that all supported versions are impacted and that the vendor has released emergency patches. It also highlights specific suspicious log entries and process behaviors that may indicate a compromise, urging immediate network access restrictions for internet-facing servers even in the absence of observed suspicious activity.

PaperCut has released emergency patches for a zero-day vulnerability affecting its NG and MF print management software, urging immediate installation and implementation of mitigations. While a CVE identifier has not yet been assigned, the vendor has confirmed customer incidents and is treating the matter with high priority. The company also recommends disconnecting affected servers from the internet and restricting access to trusted IPs as interim security measures.

PaperCut has issued a second emergency patch, specifically addressing vulnerabilities CVE-2026-82078 and CVE-2026-81578. These newly identified CVEs are confirmed to have been exploited in the wild, indicating a continued and evolving threat landscape for the print management software. The update aims to further mitigate risks beyond the initial emergency patch.

CISA has officially added two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078, affecting PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog. These flaws, which can be chained by unauthenticated attackers to alter server configurations and execute arbitrary Java bytecode, are now confirmed to be actively exploited in the wild. CISA has set a remediation deadline of September 14, 2026, for U.S. federal agencies, underscoring the urgency for all organizations to apply patches and secure internet-exposed management interfaces.

Synthesized by Vypr AI