VYPR
advisoryPublished Aug 27, 2026· 1 source

PaperCut NG/MF Vulnerability Actively Exploited, Vendor Warns

PaperCut Software has issued a critical warning about an unspecified vulnerability in its PaperCut NG and PaperCut MF print management solutions, confirming active exploitation and customer incidents.

PaperCut Software has alerted its users to an unspecified vulnerability affecting its widely deployed PaperCut NG and PaperCut MF print management solutions, confirming that the flaw is currently being actively exploited in the wild. The company stated, "We are aware of confirmed customer incidents and are treating this matter with the highest priority." This advisory comes as a significant concern for organizations relying on PaperCut for managing their printing infrastructure.

PaperCut NG is a popular print management software designed for environments such as offices, schools, and other institutions. Its counterpart, PaperCut MF (Multi-Function), is an enhanced version that integrates directly with all-in-one office copier machines, enabling management of print, copy, scan, and fax functions directly from the device's touchscreen. These solutions are embedded in workflows across numerous major brands of office equipment, making them a critical component of many organizations' operational security.

The security bulletin released by PaperCut strongly suggests a remotely exploitable nature for this vulnerability. The vendor explicitly advised, "If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses)." The Application Server acts as the central control unit for both PaperCut NG and MF, typically deployed as a single instance within an organization.

While PaperCut Software is still actively investigating the full scope and technical details of the exploit, they have committed to publishing specific indicators of compromise (IOCs) once they are identified. In the interim, customers are urged to remain vigilant for general signs of compromise. These include alerts from security tools pointing to suspicious post-exploitation activity on the PaperCut Application Server (specifically involving pc-app.exe), unexpected modifications or deletions of server.log files, or the presence of specific error messages within the logs such as "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST."

Even in the absence of these specific indicators, PaperCut's advisory emphasizes the critical need to restrict external access to the Application Server. The vendor recommends implementing firewall rules, network access controls, or equivalent security measures to ensure that the web interfaces of the PaperCut server are not reachable from untrusted internet addresses. This proactive step is crucial for mitigating the risk of exploitation while the investigation continues.

This incident echoes past security concerns surrounding PaperCut software. In 2023, threat actors associated with the Clop and LockBit ransomware operations successfully exploited two known vulnerabilities, CVE-2023-27350 and CVE-2023-27351. These flaws allowed for remote code execution and information disclosure, highlighting a recurring pattern of exploitation targeting the platform's security.

The active exploitation of this new, unspecified vulnerability underscores the persistent threat landscape faced by organizations relying on print management solutions. The widespread adoption of PaperCut NG and MF in educational and corporate environments means that a successful exploit could have significant implications for data security and operational continuity. The vendor's swift warning and guidance on restricting access aim to provide immediate mitigation steps for affected customers.

Synthesized by Vypr AI