PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability — Threadlinqs Intelligence
As of 2026-08-27, PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-2171 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
PaperCut confirmed active exploitation of an as-yet-unassigned (no CVE/CVSS) vulnerability in PaperCut NG/MF print management software, with confirmed customer incidents, and is urging admins to
On August 27, 2026, PaperCut Software issued an urgent security advisory confirming that a vulnerability in PaperCut NG and PaperCut MF -- its enterprise print management software -- is being actively exploited in the wild, with confirmed incidents reported by customers. No CVE identifier or CVSS score has been assigned as of this writing; PaperCut states it is investigating with highest priority and has not yet published a patch, root-cause details, or a definitive list of affected versions.
Pending a fix, PaperCut's sole mitigation guidance is to use firewall rules, network access controls, or equivalent measures to prevent the PaperCut Application Server's web interface (default ports 9191/HTTP and 9192/HTTPS) from being reachable from the public internet -- the same class of mitigation the vendor issued for its prior unauthenticated RCE, CVE-2023-27350, which was mass-exploited by Cl0p and LockBit ransomware affiliates (tracked by Microsoft as Lace Tempest) beginning April 13, 2023, following a March 8, 2023 patch. The August 27, 2026 advisory's preliminary indicators -- anomalous activity from the legitimate pc-app.exe process, and missing, truncated, or deleted server.log files alongside the log errors 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST' -- mirror the operational pattern documented in that 2023 campaign, in which the PaperCut application process was abused to spawn PowerShell or cmd.exe for post-exploitation execution, and are consistent with anti-forensic log tampering by an intruder covering their tracks. PaperCut explicitly cautions that the absence of these indicators does not confirm a system is unaffected, and states it will publish validated IOCs and remediation guidance as they become available.
The 2023 precedent (CVE-2023-27350, CVSS 9.8, paired with the CVE-2023-27351 auth-bypass/info-disclosure companion flaw) is technically well documented and instructive for defenders watching the 2026 incident: per Horizon3.ai's root-cause analysis, the RCE stemmed from a 'session puzzling' logic flaw in the `SetupCompleted` class (`biz/papercut/pcng/web/setup/SetupCompleted.java`) reachable at `/app?service=page/SetupComplete`, which improperly validated an anonymous caller's session as an authenticated Admin session. With that admin context, attackers used PaperCut's legitimate 'Device Scripting' feature to inject malicious JavaScript into a printer script, which the PaperCut Windows service then executed as `NT AUTHORITY\SYSTEM` -- turning an authentication-logic bug into full SYSTEM-level remote code execution without any memory-corruption exploit. Per CISA/FBI joint advisory AA23-131A and subsequent vendor/researcher reporting (Microsoft, Trend Micro, Rapid7, SecurityScorecard), the observed 2023 post-exploitation chain ran PowerShell from the PaperCut process to download and execute the TrueBot downloader (operated by the Silence group, linked to TA505 and to the Cl0p/Lace Tempest-DEV-0950/FIN11 ecosystem), which performed system-information collection and screen capture before fetching a Cobalt Strike beacon (and, in some intrusions, the FlawedGrace RAT or the DiceLoader C2 implant) used to expand access to the Active Directory server for lateral movement; some intrusions ended in Bl00dy-branded ransom notes, while Cl0p-linked activity instead used the legitimate MEGAsync client to exfiltrate stolen files, and the Bl00dy operators were observed routing malicious traffic through Tor and other proxies to mask it. CISA/FBI and SecurityScorecard published associated 2023 C2 domains (e.g. windowservicecemter[.]com, anydeskupdate[.]com, updateservicecenter[.]com) and hosting IPs. None of this 2023 tooling, infrastructure, or attribution is confirmed for the August 2026 incident -- it is included as sourced historical precedent for the same vulnerability class and vendor, to give defenders a concrete detection target while PaperCut's inv
Target sectors: education
Timeline
- PaperCut releases patched versions 20.1.7, 21.2.11, and 22.0.9 fixing CVE-2023-27350 (unauthenticated RCE) and CVE-2023-27351 (auth bypass / info disclosure) in the same product line.
- Per Microsoft's incident timeline, Cl0p-affiliated actors begin gaining initial access to targeted corporate networks by exploiting the then-unpatched CVE-2023-27350 authentication bypass.
- PaperCut confirms active in-the-wild exploitation of CVE-2023-27350; Cl0p and LockBit ransomware affiliates (Microsoft-tracked as Lace Tempest) begin mass-exploiting internet-facing PaperCut Application Servers.
- Trend Micro publishes technical analysis of the CVE-2023-27350 exploitation chain, urging immediate patching amid confirmed active exploitation.
- Microsoft publicly attributes the PaperCut exploitation wave to Cl0p and LockBit ransomware affiliates; reporting details the TrueBot-to-Cobalt Strike post-exploitation chain and MEGAsync-based data exfiltration.
- CISA and the FBI publish joint advisory AA23-131A documenting the CVE-2023-27350/27351 exploitation campaign, associated malware (TrueBot, DiceLoader, Cobalt Strike), and indicators of compromise.
- Rapid7 publishes an emerging threat report on ongoing CVE-2023-27350 exploitation, including detection guidance for PaperCut processes spawning PowerShell or cmd.exe.
- PaperCut publishes a separate security bulletin disclosing CVE-2026-8793 (insufficient brute-force protection), recommending upgrade to version 26.0.3 or later; unrelated to the vulnerability later confirmed under active exploitation.
- PaperCut issues an urgent security advisory confirming active exploitation of a new, not-yet-CVE-assigned vulnerability in PaperCut NG/MF, citing confirmed customer incidents.
- PaperCut publishes preliminary indicators of compromise (suspicious pc-app.exe activity; missing, truncated, or deleted server.log files; specific JDBC/DatabaseUtils error strings) and urges immediate restriction of Application Server internet access pending a patch.
- Help Net Security reports on the PaperCut advisory, the source feed that triggered this threat record.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1190, T1133, T1059.007, T1059.001, T1059.003, T1036, T1685.006, T1090.003, T1071.001, T1082