PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability

PaperCut NG/MF Print Management Software Under Active (TL-2026-2171) is a high-severity software vulnerability, first published 2026-08-27. It has no confirmed attribution, affects PaperCut Software PaperCut NG, maps to 13 MITRE ATT&CK techniques (T1021, T1036, T1059.001), and is covered by 9 detection rules and 26 indicators of compromise.

Key facts for TL-2026-2171

Threat ID
TL-2026-2171
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
2026-08-27
Last reviewed
2026-08-27
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
education
Detection rules
9
Indicators of compromise
26

Malware and tooling in PaperCut NG/MF Print Management Software Under Active

Malware and tooling: Bl00dy, Clop, FlawedGrace, Lizar - S0681, LockBit, Silence, Cobalt Strike, MEGAsync, cmd - S0106, powershell.exe

PaperCut confirmed active exploitation of an as-yet-unassigned (no CVE/CVSS) vulnerability in PaperCut NG/MF print management software, with confirmed customer incidents, and is urging admins to immediately restrict internet access to the Application Server pending a patch.

How PaperCut NG/MF Print Management Software Under Active works

On August 27, 2026, PaperCut Software issued an urgent security advisory confirming that a vulnerability in PaperCut NG and PaperCut MF -- its enterprise print management software -- is being actively exploited in the wild, with confirmed incidents reported by customers. No CVE identifier or CVSS score has been assigned as of this writing; PaperCut states it is investigating with highest priority and has not yet published a patch, root-cause details, or a definitive list of affected versions.

Pending a fix, PaperCut's sole mitigation guidance is to use firewall rules, network access controls, or equivalent measures to prevent the PaperCut Application Server's web interface (default ports 9191/HTTP and 9192/HTTPS) from being reachable from the public internet -- the same class of mitigation the vendor issued for its prior unauthenticated RCE, CVE-2023-27350, which was mass-exploited by Cl0p and LockBit ransomware affiliates (tracked by Microsoft as Lace Tempest) beginning April 13, 2023, following a March 8, 2023 patch. The August 27, 2026 advisory's preliminary indicators -- anomalous activity from the legitimate pc-app.exe process, and missing, truncated, or deleted server.log files alongside the log errors 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST' -- mirror the operational pattern documented in that 2023 campaign, in which the PaperCut application process was abused to spawn PowerShell or cmd.exe for post-exploitation execution, and are consistent with anti-forensic log tampering by an intruder covering their tracks. PaperCut explicitly cautions that the absence of these indicators does not confirm a system is unaffected, and states it will publish validated IOCs and remediation guidance as they become available.

The 2023 precedent (CVE-2023-27350, CVSS 9.8, paired with the CVE-2023-27351 auth-bypass/info-disclosure companion flaw) is technically well documented and instructive for defenders watching the 2026 incident: per Horizon3.ai's root-cause analysis, the RCE stemmed from a 'session puzzling' logic flaw in the `SetupCompleted` class (`biz/papercut/pcng/web/setup/SetupCompleted.java`) reachable at `/app?service=page/SetupComplete`, which improperly validated an anonymous caller's session as an authenticated Admin session. With that admin context, attackers used PaperCut's legitimate 'Device Scripting' feature to inject malicious JavaScript into a printer script, which the PaperCut Windows service then executed as `NT AUTHORITY\SYSTEM` -- turning an authentication-logic bug into full SYSTEM-level remote code execution without any memory-corruption exploit. Per CISA/FBI joint advisory AA23-131A and subsequent vendor/researcher reporting (Microsoft, Trend Micro, Rapid7, SecurityScorecard), the observed 2023 post-exploitation chain ran PowerShell from the PaperCut process to download and execute the TrueBot downloader (operated by the Silence group, linked to TA505 and to the Cl0p/Lace Tempest-DEV-0950/FIN11 ecosystem), which performed system-information collection and screen capture before fetching a Cobalt Strike beacon (and, in some intrusions, the FlawedGrace RAT or the DiceLoader C2 implant) used to expand access to the Active Directory server for lateral movement; some intrusions ended in Bl00dy-branded ransom notes, while Cl0p-linked activity instead used the legitimate MEGAsync client to exfiltrate stolen files, and the Bl00dy operators were observed routing malicious traffic through Tor and other proxies to mask it. CISA/FBI and SecurityScorecard published associated 2023 C2 domains (e.g. windowservicecemter[.]com, anydeskupdate[.]com, updateservicecenter[.]com) and hosting IPs. None of this 2023 tooling, infrastructure, or attribution is confirmed for the August 2026 incident -- it is included as sourced historical precedent for the same vulnerability class and vendor, to give defenders a concrete detection target while PaperCut's investigation is ongoing.

Separately, on August 3, 2026, PaperCut disclosed CVE-2026-8793, an insufficient brute-force-protection weakness fixed in version 26.0.3. That CVE is unrelated to the vulnerability under active exploitation described in the August 27 advisory, and there is no evidence connecting the two at this time.

Because PaperCut NG/MF Application Servers are widely deployed as internet-facing print management infrastructure (roughly 1,700 internet-exposed instances were identified during the 2023 campaign, several hundred in the education sector) and no patch yet exists for the actively exploited flaw, organizations should treat any publicly reachable Application Server as an immediate risk, apply the vendor's network-restriction guidance now, and monitor for the documented indicators.

MITRE ATT&CK techniques used in TL-2026-2171

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy

Discovery

T1082 System Information Discovery

Collection

T1113 Screen Capture

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Exfiltration

T1567.002 Exfiltration to Cloud Storage

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in PaperCut NG/MF Print Management Software Under Active

  • PaperCut Software — PaperCut NG
    Vulnerable versions: unconfirmed pending vendor investigation
  • PaperCut Software — PaperCut MF
    Vulnerable versions: unconfirmed pending vendor investigation

Remediation for PaperCut NG/MF Print Management Software Under Active

Patches

  • No vendor patch is available yet for the vulnerability under active exploitation as of 2026-08-27; PaperCut is investigating and preparing a fix

Immediate actions

  • Restrict all network access to the PaperCut NG/MF Application Server web interface (default ports 9191/HTTP and 9192/HTTPS) to trusted, internal IP addresses only via firewall rules or network access controls
  • Do not expose the PaperCut Application Server directly to the public internet
  • Review server.log for the documented error strings ('ERROR No suitable driver found for jdbc:no:x', 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST') and for missing, unexpectedly truncated, or deleted log files
  • Monitor for suspicious process activity originating from pc-app.exe via EDR, IDS, or network-monitoring tooling
  • As a defense-in-depth measure informed by the 2023 precedent, monitor PaperCut application logs for unexpected admin-interface logins and for modifications to the 'print.script.sandboxed' / 'print-and-device.script.enabled' config keys, which indicate abuse of the Device Scripting feature for code execution

Workarounds

  • Use firewall rules or equivalent network access controls to restrict the Application Server web interface to trusted internal IP addresses only, per PaperCut's urgent guidance

Longer-term hardening

  • Apply the vendor patch as soon as PaperCut publishes one for the vulnerability under active exploitation
  • Upgrade to PaperCut NG/MF 26.0.3 or later to remediate the separately disclosed CVE-2026-8793 brute-force-protection weakness
  • Segment print management infrastructure from general-purpose network access and enforce least-privilege network paths to the Application Server
  • Subscribe to PaperCut's security bulletin feed and monitor its knowledge base for updated indicators of compromise and patch availability

Timeline of PaperCut NG/MF Print Management Software Under Active

  • PaperCut releases patched versions 20.1.7, 21.2.11, and 22.0.9 fixing CVE-2023-27350 (unauthenticated RCE) and CVE-2023-27351 (auth bypass / info disclosure) in the same product line.
  • Per Microsoft's incident timeline, Cl0p-affiliated actors begin gaining initial access to targeted corporate networks by exploiting the then-unpatched CVE-2023-27350 authentication bypass.
  • PaperCut confirms active in-the-wild exploitation of CVE-2023-27350; Cl0p and LockBit ransomware affiliates (Microsoft-tracked as Lace Tempest) begin mass-exploiting internet-facing PaperCut Application Servers.
  • Trend Micro publishes technical analysis of the CVE-2023-27350 exploitation chain, urging immediate patching amid confirmed active exploitation.
  • Microsoft publicly attributes the PaperCut exploitation wave to Cl0p and LockBit ransomware affiliates; reporting details the TrueBot-to-Cobalt Strike post-exploitation chain and MEGAsync-based data exfiltration.
  • CISA and the FBI publish joint advisory AA23-131A documenting the CVE-2023-27350/27351 exploitation campaign, associated malware (TrueBot, DiceLoader, Cobalt Strike), and indicators of compromise.
  • Rapid7 publishes an emerging threat report on ongoing CVE-2023-27350 exploitation, including detection guidance for PaperCut processes spawning PowerShell or cmd.exe.
  • PaperCut publishes a separate security bulletin disclosing CVE-2026-8793 (insufficient brute-force protection), recommending upgrade to version 26.0.3 or later; unrelated to the vulnerability later confirmed under active exploitation.
  • Help Net Security reports on the PaperCut advisory, the source feed that triggered this threat record.
  • PaperCut publishes preliminary indicators of compromise (suspicious pc-app.exe activity; missing, truncated, or deleted server.log files; specific JDBC/DatabaseUtils error strings) and urges immediate restriction of Application Server internet access pending a patch.
  • PaperCut issues an urgent security advisory confirming active exploitation of a new, not-yet-CVE-assigned vulnerability in PaperCut NG/MF, citing confirmed customer incidents.

Sources cited for PaperCut NG/MF Print Management Software Under Active

More in vulnerability

Detection coverage for TL-2026-2171

As of 2026-08-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2171 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats