Threat reportVulnerabilityTL-2026-2178

PaperCut NG/MF Actively Exploited Zero-Day Vulnerability Affects All Supported Versions (No CVE Assigned)

criticalACTIVE

PaperCut NG/MF Actively Exploited Zero-Day Vulnerability (TL-2026-2178) is a critical-severity software vulnerability, first published 2026-08-28. It has no confirmed attribution, affects PaperCut Software Pty Ltd PaperCut NG, maps to 10 MITRE ATT&CK techniques (T1036.005, T1059.001, T1059.007), and is covered by 9 detection rules and 19 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
19Indicators of compromise

Key facts for TL-2026-2178

Threat ID
TL-2026-2178
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
education, government administration, health, corporate
Target regions
Global
Detection rules
9
Indicators of compromise
19

Malware and tooling in PaperCut NG/MF Actively Exploited Zero-Day Vulnerability

Malware and tooling: Silence, Atera, Cobalt Strike, PaperCut MF, PaperCut NG, Syncro

How PaperCut NG/MF Actively Exploited Zero-Day Vulnerability works

PaperCut issued an urgent, out-of-cycle security bulletin on 27 Aug 2026 confirming active in-the-wild exploitation of an undisclosed vulnerability affecting every currently supported version of PaperCut NG and PaperCut MF (v25 and v26) on Windows, Linux, and macOS. No CVE or CVSS score has been assigned; PaperCut shipped emergency patched builds within hours and is urging customers to remove Application Servers from the public internet.

On 27 August 2026, PaperCut Software published an URGENT security bulletin (KB: security-bulletin-27-aug-2026-urgent-security-advisory) warning that a vulnerability of unspecified type in PaperCut NG and PaperCut MF is being actively exploited in the wild. Every currently supported version (v25.x and v26.x, with a v24.x branch patch still in progress at the time of the advisory) across Windows, Linux, and macOS installers is affected, making the specific version installed irrelevant to exposure. PaperCut's security emergency response team was alerted by a university customer whose internal security and digital forensics/incident response teams identified anomalous Application Server activity; PaperCut engineers used that information to reproduce the bug and confirm real-world abuse. The company stated it is 'aware of confirmed customer incidents and [is] treating this matter with the highest priority.' At 02:10 a.m. AEST on 28 August 2026, PaperCut released emergency, out-of-cycle builds for the v25 and v26 branches (PaperCut MF 26.0.4.76494 / 25.0.12.76496; PaperCut NG 26.0.4.76495 / 25.0.12.76497) for all three OS platforms, explicitly framed as emergency releases for administrators who cannot immediately isolate public-facing servers, rather than routine updates.

Unlike PaperCut's fully-detailed 2023 advisory for CVE-2023-27350/CVE-2023-27351 (an authentication-bypass chain leading to SYSTEM-level remote code execution, published only after patches were broadly deployed), the 27-28 Aug 2026 bulletin withholds the vulnerability class and exploitation mechanism entirely — no CVE, no CVSS vector, and no root-cause description have been published as of this writing, which multiple outlets attribute to a deliberate effort to slow attacker replication while the emergency patch rolls out. What is confirmed across the vendor bulletin and subsequent reporting (BleepingComputer, Help Net Security, CyberSecurityNews, GBHackers) is that the attack surface is the PaperCut Application Server's web interface when it is reachable from the public internet — i.e., remote exploitation of an internet-facing application server — and that PaperCut and independent analysts expect opportunistic, version-agnostic scanning of any exposed instance, consistent with the pattern observed after PaperCut's prior actively-exploited flaws.

PaperCut published a narrow set of host-based compromise indicators rather than network infrastructure IOCs: anomalous/suspicious activity originating from the legitimate pc-app.exe Application Server process, and server.log files that are missing, truncated, or deleted — noting explicitly that the absence of these artifacts does NOT rule out a breach. Two specific anomalous log error strings were called out: 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST', both suggesting interference with the Application Server's backend database/JDBC layer and its print-quota cardID lookup logic during exploitation attempts.

This is not PaperCut's first actively-exploited, internet-facing flaw, and the 2023 precedent is directly instructive for defenders because its full exploit chain and post-exploitation behavior are public. CVE-2023-27350 (responsibly disclosed 10 Jan 2023, patched 8 Mar 2023 in versions 20.1.7/21.2.11/22.0.9, CVSS 9.8) let an unauthenticated attacker reach PaperCut's 'SetupCompleted' setup-wizard page and click 'Login' to obtain full admin access with no credentials; from there, the attacker flipped the 'print-and-device.script.enabled' and 'print.script.sandboxed' settings to disable JavaScript sandboxing and saved a malicious printer script that executed immediately in the embedded Rhino JavaScript engine, yielding code execution as NT AUTHORITY\SYSTEM. Its companion, CVE-2023-27351 (CVSS 8.2), was an unauthenticated data-disclosure flaw fixed by the same patch. PaperCut confirmed active exploitation on 19 April 2023, and CISA/FBI/MS-ISAC documented Bl00dy ransomware affiliates using CVE-2023-27350 for initial access in advisory AA23-131A. Huntress incident-response telemetry from the same campaign recorded an initial-access wave on 16 April 2023 (PowerShell 'Invoke-WebRequest' pulling setup.msi from upd488.windowservicecemter[.]com, followed by a silent msiexec install) and a secondary, more opportunistic wave on 22 April 2023 that deployed a Monero cryptominer via encoded PowerShell that first attempted to disable Windows Defender and remove competing miners. The same campaign dropped the Truebot downloader DLL, and infrastructure analysis linked Cobalt Strike Beacon C2 and abuse of legitimate remote-management tools (Atera, Syncro) for persistence — with Cl0p and LockBit ransomware affiliates and Iranian nation-state-linked actors also exploiting the same authentication-bypass chain for their own campaigns. A separate PaperCut CSRF flaw, CVE-2023-2533, was added to the CISA KEV catalog on 28 July 2025 citing active exploitation, with a BOD 22-01 remediation deadline of 18 August 2025.

PaperCut has also disclosed two unrelated, lower-severity NG/MF authentication flaws earlier in the same month as this zero-day: CVE-2026-8793 (3 Aug 2026, CVSS 6.9, CWE-307 — insufficient rate-limiting on login attempts enabling brute-force/credential-stuffing) and CVE-2026-8794 (6 Aug 2026, CVSS 6.9 — a timing-oracle flaw in the authentication handler that lets an unauthenticated attacker enumerate valid usernames by measuring response-time differences in password-hash comparison). Neither is confirmed to be related to the 27-28 Aug zero-day, but together with it they show three distinct PaperCut NG/MF authentication/application-server security bulletins inside a single month — reinforcing that internet-exposed PaperCut Application Servers remain a repeatedly and actively abused enterprise attack surface, and is the primary basis for treating this new, technically-undisclosed 2026 zero-day as CRITICAL pending a CVE/CVSS assignment and public root-cause disclosure.

MITRE ATT&CK techniques used in TL-2026-2178

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Execution

T1059.001 PowerShell; T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1496 Resource Hijacking

Resource Development

T1588.006 Vulnerabilities

Reconnaissance

T1595.002 Vulnerability Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in PaperCut NG/MF Actively Exploited Zero-Day Vulnerability

  • PaperCut Software Pty Ltd — PaperCut NG
    Vulnerable versions: all currently supported versions (v25.x, v26.x); v24.x branch patch in progress
    Fixed in: 25.0.12.76497 (Windows/Linux/macOS); 26.0.4.76495 (Windows/Linux/macOS)
  • PaperCut Software Pty Ltd — PaperCut MF
    Vulnerable versions: all currently supported versions (v25.x, v26.x); v24.x branch patch in progress
    Fixed in: 25.0.12.76496 (Windows/Linux/macOS); 26.0.4.76494 (Windows/Linux/macOS)

Remediation for PaperCut NG/MF Actively Exploited Zero-Day Vulnerability

Patches

  • PaperCut MF 26.0.4.76494
  • PaperCut MF 25.0.12.76496
  • PaperCut NG 26.0.4.76495
  • PaperCut NG 25.0.12.76497
  • PaperCut NG/MF v24 branch patch (in progress at time of advisory)

Immediate actions

  • Restrict PaperCut Application Server web interfaces to trusted internal/VPN IP addresses via firewall rules or network access controls; do not leave the Application Server directly reachable from the public internet
  • Apply PaperCut's emergency out-of-cycle builds immediately: PaperCut MF 26.0.4.76494 / 25.0.12.76496 and PaperCut NG 26.0.4.76495 / 25.0.12.76497 (Windows, Linux, macOS)
  • Hunt for compromise indicators: anomalous pc-app.exe activity, and missing, truncated, or deleted server.log files — vendor notes absence of these artifacts does NOT rule out a breach

Workarounds

  • If immediate patching is not possible, fully block internet access to the Application Server web interface at the perimeter firewall until patched
  • Monitor server.log continuity/integrity as a compensating detective control for tampering

Longer-term hardening

  • Place PaperCut Application/Site Servers behind a VPN or zero-trust access proxy rather than exposing them directly to the internet
  • Segment print-management infrastructure from general enterprise network segments and from directly internet-routable subnets
  • Establish a process to apply PaperCut's out-of-cycle emergency patches promptly, given the product's repeated history of actively-exploited, internet-facing zero-days (2023, 2025, 2026)
  • Also apply the separate CVE-2026-8793 and CVE-2026-8794 authentication-handler fixes from the 3/6 Aug 2026 bulletins — this emergency patch does not address them

Timeline of PaperCut NG/MF Actively Exploited Zero-Day Vulnerability

  • CVE-2023-27350 and CVE-2023-27351 are responsibly disclosed to PaperCut, beginning the disclosure timeline for the auth-bypass RCE chain that later becomes the primary historical precedent for this new 2026 zero-day.
  • PaperCut releases patched versions 20.1.7, 21.2.11, and 22.0.9 fixing CVE-2023-27350 (CVSS 9.8 — unauthenticated SYSTEM-level RCE via the 'SetupCompleted' auth-bypass page plus a Rhino-JavaScript printer-script sandbox bypass) and CVE-2023-27351 (CVSS 8.2 — unauthenticated data disclosure).
  • Prior PaperCut NG/MF unauthenticated auth-bypass RCE chain (CVE-2023-27350/CVE-2023-27351) begins active in-the-wild exploitation by Cl0p, LockBit, Bl00dy, and Iranian nation-state-linked actors — the precedent driving the CRITICAL rating for this undisclosed 2026 flaw.
  • PaperCut publicly confirms active in-the-wild exploitation of CVE-2023-27350 against unpatched Application Servers.
  • A secondary, more opportunistic wave of CVE-2023-27350 exploitation deploys a Monero cryptominer via encoded PowerShell that first attempts to disable Windows Defender and remove competing miners, per Huntress incident-response findings.
  • CISA adds a separate PaperCut NG/MF CSRF vulnerability (CVE-2023-2533) to its Known Exploited Vulnerabilities catalog, citing active exploitation and setting a federal remediation deadline of 18 Aug 2025.
  • PaperCut discloses CVE-2026-8793 (CVSS 6.9, CWE-307 — insufficient rate-limiting on authentication attempts enabling brute-force/credential-stuffing), a separate PaperCut NG/MF flaw not confirmed to be related to the 27-28 Aug zero-day.
  • PaperCut discloses CVE-2026-8794 (CVSS 6.9), a timing-oracle username-enumeration flaw in the PaperCut NG/MF authentication handler, separate from the 27-28 Aug zero-day but part of the same month's cluster of NG/MF authentication-related bulletins.
  • PaperCut publishes an URGENT out-of-cycle security bulletin; no CVE, CVSS score, or root-cause/vulnerability-class detail is disclosed, and customers are urged to restrict internet access to Application Servers.
  • PaperCut engineers reproduce the vulnerability using the customer-supplied information and confirm active in-the-wild exploitation affecting every currently supported version of PaperCut NG/MF.
  • A university customer's internal security and digital forensics/incident response teams identify anomalous PaperCut Application Server activity and alert PaperCut's security emergency response team.
  • GBHackers, BleepingComputer, Help Net Security, and CyberSecurityNews publish coverage of the advisory and emergency patches, drawing direct comparisons to PaperCut's 2023 exploitation history; GBHackers' report is the trigger source for this threat record.
  • Reporting confirms the v24.x branch patch is still being finalized while v25/v26 emergency builds are already available for download.
  • PaperCut releases emergency, out-of-cycle patched builds at 02:10 a.m. AEST for the v25 and v26 branches across Windows, Linux, and macOS (MF 26.0.4.76494 / 25.0.12.76496; NG 26.0.4.76495 / 25.0.12.76497).

Sources cited for PaperCut NG/MF Actively Exploited Zero-Day Vulnerability

Detection coverage for TL-2026-2178

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2178 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
19 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats