Threat reportVulnerabilityTL-2026-2178
PaperCut NG/MF Actively Exploited Zero-Day Vulnerability Affects All Supported Versions (No CVE Assigned)
PaperCut NG/MF Actively Exploited Zero-Day Vulnerability (TL-2026-2178) is a critical-severity software vulnerability, first published 2026-08-28. It has no confirmed attribution, affects PaperCut Software Pty Ltd PaperCut NG, maps to 10 MITRE ATT&CK techniques (T1036.005, T1059.001, T1059.007), and is covered by 9 detection rules and 19 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 19Indicators of compromise
Key facts for TL-2026-2178
- Threat ID
- TL-2026-2178
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- education, government administration, health, corporate
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in PaperCut NG/MF Actively Exploited Zero-Day Vulnerability
Malware and tooling: Silence, Atera, Cobalt Strike, PaperCut MF, PaperCut NG, Syncro
How PaperCut NG/MF Actively Exploited Zero-Day Vulnerability works
PaperCut issued an urgent, out-of-cycle security bulletin on 27 Aug 2026 confirming active in-the-wild exploitation of an undisclosed vulnerability affecting every currently supported version of PaperCut NG and PaperCut MF (v25 and v26) on Windows, Linux, and macOS. No CVE or CVSS score has been assigned; PaperCut shipped emergency patched builds within hours and is urging customers to remove Application Servers from the public internet.
On 27 August 2026, PaperCut Software published an URGENT security bulletin (KB: security-bulletin-27-aug-2026-urgent-security-advisory) warning that a vulnerability of unspecified type in PaperCut NG and PaperCut MF is being actively exploited in the wild. Every currently supported version (v25.x and v26.x, with a v24.x branch patch still in progress at the time of the advisory) across Windows, Linux, and macOS installers is affected, making the specific version installed irrelevant to exposure. PaperCut's security emergency response team was alerted by a university customer whose internal security and digital forensics/incident response teams identified anomalous Application Server activity; PaperCut engineers used that information to reproduce the bug and confirm real-world abuse. The company stated it is 'aware of confirmed customer incidents and [is] treating this matter with the highest priority.' At 02:10 a.m. AEST on 28 August 2026, PaperCut released emergency, out-of-cycle builds for the v25 and v26 branches (PaperCut MF 26.0.4.76494 / 25.0.12.76496; PaperCut NG 26.0.4.76495 / 25.0.12.76497) for all three OS platforms, explicitly framed as emergency releases for administrators who cannot immediately isolate public-facing servers, rather than routine updates.
Unlike PaperCut's fully-detailed 2023 advisory for CVE-2023-27350/CVE-2023-27351 (an authentication-bypass chain leading to SYSTEM-level remote code execution, published only after patches were broadly deployed), the 27-28 Aug 2026 bulletin withholds the vulnerability class and exploitation mechanism entirely — no CVE, no CVSS vector, and no root-cause description have been published as of this writing, which multiple outlets attribute to a deliberate effort to slow attacker replication while the emergency patch rolls out. What is confirmed across the vendor bulletin and subsequent reporting (BleepingComputer, Help Net Security, CyberSecurityNews, GBHackers) is that the attack surface is the PaperCut Application Server's web interface when it is reachable from the public internet — i.e., remote exploitation of an internet-facing application server — and that PaperCut and independent analysts expect opportunistic, version-agnostic scanning of any exposed instance, consistent with the pattern observed after PaperCut's prior actively-exploited flaws.
PaperCut published a narrow set of host-based compromise indicators rather than network infrastructure IOCs: anomalous/suspicious activity originating from the legitimate pc-app.exe Application Server process, and server.log files that are missing, truncated, or deleted — noting explicitly that the absence of these artifacts does NOT rule out a breach. Two specific anomalous log error strings were called out: 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST', both suggesting interference with the Application Server's backend database/JDBC layer and its print-quota cardID lookup logic during exploitation attempts.
This is not PaperCut's first actively-exploited, internet-facing flaw, and the 2023 precedent is directly instructive for defenders because its full exploit chain and post-exploitation behavior are public. CVE-2023-27350 (responsibly disclosed 10 Jan 2023, patched 8 Mar 2023 in versions 20.1.7/21.2.11/22.0.9, CVSS 9.8) let an unauthenticated attacker reach PaperCut's 'SetupCompleted' setup-wizard page and click 'Login' to obtain full admin access with no credentials; from there, the attacker flipped the 'print-and-device.script.enabled' and 'print.script.sandboxed' settings to disable JavaScript sandboxing and saved a malicious printer script that executed immediately in the embedded Rhino JavaScript engine, yielding code execution as NT AUTHORITY\SYSTEM. Its companion, CVE-2023-27351 (CVSS 8.2), was an unauthenticated data-disclosure flaw fixed by the same patch. PaperCut confirmed active exploitation on 19 April 2023, and CISA/FBI/MS-ISAC documented Bl00dy ransomware affiliates using CVE-2023-27350 for initial access in advisory AA23-131A. Huntress incident-response telemetry from the same campaign recorded an initial-access wave on 16 April 2023 (PowerShell 'Invoke-WebRequest' pulling setup.msi from upd488.windowservicecemter[.]com, followed by a silent msiexec install) and a secondary, more opportunistic wave on 22 April 2023 that deployed a Monero cryptominer via encoded PowerShell that first attempted to disable Windows Defender and remove competing miners. The same campaign dropped the Truebot downloader DLL, and infrastructure analysis linked Cobalt Strike Beacon C2 and abuse of legitimate remote-management tools (Atera, Syncro) for persistence — with Cl0p and LockBit ransomware affiliates and Iranian nation-state-linked actors also exploiting the same authentication-bypass chain for their own campaigns. A separate PaperCut CSRF flaw, CVE-2023-2533, was added to the CISA KEV catalog on 28 July 2025 citing active exploitation, with a BOD 22-01 remediation deadline of 18 August 2025.
PaperCut has also disclosed two unrelated, lower-severity NG/MF authentication flaws earlier in the same month as this zero-day: CVE-2026-8793 (3 Aug 2026, CVSS 6.9, CWE-307 — insufficient rate-limiting on login attempts enabling brute-force/credential-stuffing) and CVE-2026-8794 (6 Aug 2026, CVSS 6.9 — a timing-oracle flaw in the authentication handler that lets an unauthenticated attacker enumerate valid usernames by measuring response-time differences in password-hash comparison). Neither is confirmed to be related to the 27-28 Aug zero-day, but together with it they show three distinct PaperCut NG/MF authentication/application-server security bulletins inside a single month — reinforcing that internet-exposed PaperCut Application Servers remain a repeatedly and actively abused enterprise attack surface, and is the primary basis for treating this new, technically-undisclosed 2026 zero-day as CRITICAL pending a CVE/CVSS assignment and public root-cause disclosure.
MITRE ATT&CK techniques used in TL-2026-2178
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Execution
T1059.001 PowerShell; T1059.007 JavaScript
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools
Initial Access
T1190 Exploit Public-Facing Application
Impact
Resource Development
Reconnaissance
T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in PaperCut NG/MF Actively Exploited Zero-Day Vulnerability
- PaperCut Software Pty Ltd — PaperCut NG
Vulnerable versions: all currently supported versions (v25.x, v26.x); v24.x branch patch in progress
Fixed in: 25.0.12.76497 (Windows/Linux/macOS); 26.0.4.76495 (Windows/Linux/macOS) - PaperCut Software Pty Ltd — PaperCut MF
Vulnerable versions: all currently supported versions (v25.x, v26.x); v24.x branch patch in progress
Fixed in: 25.0.12.76496 (Windows/Linux/macOS); 26.0.4.76494 (Windows/Linux/macOS)
Remediation for PaperCut NG/MF Actively Exploited Zero-Day Vulnerability
Patches
- PaperCut MF 26.0.4.76494
- PaperCut MF 25.0.12.76496
- PaperCut NG 26.0.4.76495
- PaperCut NG 25.0.12.76497
- PaperCut NG/MF v24 branch patch (in progress at time of advisory)
Immediate actions
- Restrict PaperCut Application Server web interfaces to trusted internal/VPN IP addresses via firewall rules or network access controls; do not leave the Application Server directly reachable from the public internet
- Apply PaperCut's emergency out-of-cycle builds immediately: PaperCut MF 26.0.4.76494 / 25.0.12.76496 and PaperCut NG 26.0.4.76495 / 25.0.12.76497 (Windows, Linux, macOS)
- Hunt for compromise indicators: anomalous pc-app.exe activity, and missing, truncated, or deleted server.log files — vendor notes absence of these artifacts does NOT rule out a breach
Workarounds
- If immediate patching is not possible, fully block internet access to the Application Server web interface at the perimeter firewall until patched
- Monitor server.log continuity/integrity as a compensating detective control for tampering
Longer-term hardening
- Place PaperCut Application/Site Servers behind a VPN or zero-trust access proxy rather than exposing them directly to the internet
- Segment print-management infrastructure from general enterprise network segments and from directly internet-routable subnets
- Establish a process to apply PaperCut's out-of-cycle emergency patches promptly, given the product's repeated history of actively-exploited, internet-facing zero-days (2023, 2025, 2026)
- Also apply the separate CVE-2026-8793 and CVE-2026-8794 authentication-handler fixes from the 3/6 Aug 2026 bulletins — this emergency patch does not address them
Timeline of PaperCut NG/MF Actively Exploited Zero-Day Vulnerability
- CVE-2023-27350 and CVE-2023-27351 are responsibly disclosed to PaperCut, beginning the disclosure timeline for the auth-bypass RCE chain that later becomes the primary historical precedent for this new 2026 zero-day.
- PaperCut releases patched versions 20.1.7, 21.2.11, and 22.0.9 fixing CVE-2023-27350 (CVSS 9.8 — unauthenticated SYSTEM-level RCE via the 'SetupCompleted' auth-bypass page plus a Rhino-JavaScript printer-script sandbox bypass) and CVE-2023-27351 (CVSS 8.2 — unauthenticated data disclosure).
- Prior PaperCut NG/MF unauthenticated auth-bypass RCE chain (CVE-2023-27350/CVE-2023-27351) begins active in-the-wild exploitation by Cl0p, LockBit, Bl00dy, and Iranian nation-state-linked actors — the precedent driving the CRITICAL rating for this undisclosed 2026 flaw.
- PaperCut publicly confirms active in-the-wild exploitation of CVE-2023-27350 against unpatched Application Servers.
- A secondary, more opportunistic wave of CVE-2023-27350 exploitation deploys a Monero cryptominer via encoded PowerShell that first attempts to disable Windows Defender and remove competing miners, per Huntress incident-response findings.
- CISA adds a separate PaperCut NG/MF CSRF vulnerability (CVE-2023-2533) to its Known Exploited Vulnerabilities catalog, citing active exploitation and setting a federal remediation deadline of 18 Aug 2025.
- PaperCut discloses CVE-2026-8793 (CVSS 6.9, CWE-307 — insufficient rate-limiting on authentication attempts enabling brute-force/credential-stuffing), a separate PaperCut NG/MF flaw not confirmed to be related to the 27-28 Aug zero-day.
- PaperCut discloses CVE-2026-8794 (CVSS 6.9), a timing-oracle username-enumeration flaw in the PaperCut NG/MF authentication handler, separate from the 27-28 Aug zero-day but part of the same month's cluster of NG/MF authentication-related bulletins.
- PaperCut publishes an URGENT out-of-cycle security bulletin; no CVE, CVSS score, or root-cause/vulnerability-class detail is disclosed, and customers are urged to restrict internet access to Application Servers.
- PaperCut engineers reproduce the vulnerability using the customer-supplied information and confirm active in-the-wild exploitation affecting every currently supported version of PaperCut NG/MF.
- A university customer's internal security and digital forensics/incident response teams identify anomalous PaperCut Application Server activity and alert PaperCut's security emergency response team.
- GBHackers, BleepingComputer, Help Net Security, and CyberSecurityNews publish coverage of the advisory and emergency patches, drawing direct comparisons to PaperCut's 2023 exploitation history; GBHackers' report is the trigger source for this threat record.
- Reporting confirms the v24.x branch patch is still being finalized while v25/v26 emergency builds are already available for download.
- PaperCut releases emergency, out-of-cycle patched builds at 02:10 a.m. AEST for the v25 and v26 branches across Windows, Linux, and macOS (MF 26.0.4.76494 / 25.0.12.76496; NG 26.0.4.76495 / 25.0.12.76497).
Sources cited for PaperCut NG/MF Actively Exploited Zero-Day Vulnerability
- PaperCut warns of actively exploited vulnerability
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
- PaperCut warns of NG, MF flaw exploited in zero-day attacks
- Unknown PaperCut NG/MF vulnerability is under active attack
- PaperCut NG/MF Vulnerability Actively Exploited in Attack - All Versions Impacted
- Critical Vulnerabilities in PaperCut Print Management Software (CVE-2023-27350/27351)
- CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation
- PaperCut Security Vulnerability Log
- Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (Alert AA23-131A)
- CVE-2023-27350: Ongoing Exploitation of PaperCut Vulnerability
- CVE-2026-8794: PaperCut NG/MF Auth Bypass Vulnerability
- CVE-2026-8793 - PaperCut NG/MF: Insufficient brute-force protection
Detection coverage for TL-2026-2178
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2178 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.