# PaperCut NG/MF Actively Exploited Zero-Day Vulnerability Affects All Supported Versions (No CVE Assigned)

> PaperCut issued an urgent, out-of-cycle security bulletin on 27 Aug 2026 confirming active in-the-wild exploitation of an undisclosed vulnerability affecting every currently supported version of PaperCut NG and PaperCut MF (v25 and v26) on Windows, Linux, and macOS. No CVE or CVSS score has been assigned; PaperCut shipped emergency patched builds within hours and is urging customers to remove Application Servers from the public internet.

- **Published:** 2026-08-28T00:00:00Z
- **Last reviewed:** 2026-08-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2178
- **ID:** TL-2026-2178
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 27 August 2026, PaperCut Software published an URGENT security bulletin (KB: security-bulletin-27-aug-2026-urgent-security-advisory) warning that a vulnerability of unspecified type in PaperCut NG and PaperCut MF is being actively exploited in the wild. Every currently supported version (v25.x and v26.x, with a v24.x branch patch still in progress at the time of the advisory) across Windows, Linux, and macOS installers is affected, making the specific version installed irrelevant to exposure. PaperCut's security emergency response team was alerted by a university customer whose internal security and digital forensics/incident response teams identified anomalous Application Server activity; PaperCut engineers used that information to reproduce the bug and confirm real-world abuse. The company stated it is 'aware of confirmed customer incidents and [is] treating this matter with the highest priority.' At 02:10 a.m. AEST on 28 August 2026, PaperCut released emergency, out-of-cycle builds for the v25 and v26 branches (PaperCut MF 26.0.4.76494 / 25.0.12.76496; PaperCut NG 26.0.4.76495 / 25.0.12.76497) for all three OS platforms, explicitly framed as emergency releases for administrators who cannot immediately isolate public-facing servers, rather than routine updates.

Unlike PaperCut's fully-detailed 2023 advisory for CVE-2023-27350/CVE-2023-27351 (an authentication-bypass chain leading to SYSTEM-level remote code execution, published only after patches were broadly deployed), the 27-28 Aug 2026 bulletin withholds the vulnerability class and exploitation mechanism entirely — no CVE, no CVSS vector, and no root-cause description have been published as of this writing, which multiple outlets attribute to a deliberate effort to slow attacker replication while the emergency patch rolls out. What is confirmed across the vendor bulletin and subsequent reporting (BleepingComputer, Help Net Security, CyberSecurityNews, GBHackers) is that the attack surface is the PaperCut Application Server's web interface when it is reachable from the public internet — i.e., remote exploitation of an internet-facing application server — and that PaperCut and independent analysts expect opportunistic, version-agnostic scanning of any exposed instance, consistent with the pattern observed after PaperCut's prior actively-exploited flaws.

PaperCut published a narrow set of host-based compromise indicators rather than network infrastructure IOCs: anomalous/suspicious activity originating from the legitimate pc-app.exe Application Server process, and server.log files that are missing, truncated, or deleted — noting explicitly that the absence of these artifacts does NOT rule out a breach. Two specific anomalous log error strings were called out: 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST', both suggesting interference with the Application Server's backend database/JDBC layer and its print-quota cardID lookup logic during exploitation attempts.

This is not PaperCut's first actively-exploited, internet-facing flaw, and the 2023 precedent is directly instructive for defenders because its full exploit chain and post-exploitation behavior are public. CVE-2023-27350 (responsibly disclosed 10 Jan 2023, patched 8 Mar 2023 in versions 20.1.7/21.2.11/22.0.9, CVSS 9.8) let an unauthenticated attacker reach PaperCut's 'SetupCompleted' setup-wizard page and click 'Login' to obtain full admin access with no credentials; from there, the attacker flipped the 'print-and-device.script.enabled' and 'print.script.sandboxed' settings to disable JavaScript sandboxing and saved a malicious printer script that executed immediately in the embedded Rhino JavaScript engine, yielding code execution as NT AUTHORITY\SYSTEM. Its companion, CVE-2023-27351 (CVSS 8.2), was an unauthenticated data-disclosure flaw fixed by the same patch. PaperCut confirmed active exploitation on 19 April 2023, and CISA/FBI/MS-ISAC documented Bl00dy ransomware affiliates using CVE-2023-27350 for initial access in advisory AA23-131A. Huntress incident-response telemetry from the same campaign recorded an initial-access wave on 16 April 2023 (PowerShell 'Invoke-WebRequest' pulling setup.msi from upd488.windowservicecemter[.]com, followed by a silent msiexec install) and a secondary, more opportunistic wave on 22 April 2023 that deployed a Monero cryptominer via encoded PowerShell that first attempted to disable Windows Defender and remove competing miners. The same campaign dropped the Truebot downloader DLL, and infrastructure analysis linked Cobalt Strike Beacon C2 and abuse of legitimate remote-management tools (Atera, Syncro) for persistence — with Cl0p and LockBit ransomware affiliates and Iranian nation-state-linked actors also exploiting the same authentication-bypass chain for their own campaigns. A separate PaperCut CSRF flaw, CVE-2023-2533, was added to the CISA KEV catalog on 28 July 2025 citing active exploitation, with a BOD 22-01 remediation deadline of 18 August 2025.

PaperCut has also disclosed two unrelated, lower-severity NG/MF authentication flaws earlier in the same month as this zero-day: CVE-2026-8793 (3 Aug 2026, CVSS 6.9, CWE-307 — insufficient rate-limiting on login attempts enabling brute-force/credential-stuffing) and CVE-2026-8794 (6 Aug 2026, CVSS 6.9 — a timing-oracle flaw in the authentication handler that lets an unauthenticated attacker enumerate valid usernames by measuring response-time differences in password-hash comparison). Neither is confirmed to be related to the 27-28 Aug zero-day, but together with it they show three distinct PaperCut NG/MF authentication/application-server security bulletins inside a single month — reinforcing that internet-exposed PaperCut Application Servers remain a repeatedly and actively abused enterprise attack surface, and is the primary basis for treating this new, technically-undisclosed 2026 zero-day as CRITICAL pending a CVE/CVSS assignment and public root-cause disclosure.

## MITRE ATT&CK

- T1588.006 Vulnerabilities
- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1059.007 JavaScript
- T1059.001 PowerShell
- T1219 Remote Access Tools
- T1071.001 Web Protocols
- T1685 Disable or Modify Tools
- T1036.005 Match Legitimate Resource Name or Location
- T1496 Resource Hijacking

## Sources

- [PaperCut warns of actively exploited vulnerability](https://gbhackers.com/papercut-warns-of-actively-exploited-vulnerability/)
- [URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)](https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/)
- [PaperCut warns of NG, MF flaw exploited in zero-day attacks](https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/)
- [Unknown PaperCut NG/MF vulnerability is under active attack](https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/)
- [PaperCut NG/MF Vulnerability Actively Exploited in Attack - All Versions Impacted](https://cybersecuritynews.com/papercut-ng-mf-vulnerability-actively-exploited/)
- [Critical Vulnerabilities in PaperCut Print Management Software (CVE-2023-27350/27351)](https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software)
- [CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation](https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html)
- [PaperCut Security Vulnerability Log](https://www.papercut.com/kb/Main/security-vulnerability-log/)
- [Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (Alert AA23-131A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-131a)
- [CVE-2023-27350: Ongoing Exploitation of PaperCut Vulnerability](https://www.rapid7.com/blog/post/2023/05/17/etr-cve-2023-27350-ongoing-exploitation-of-papercut-remote-code-execution-vulnerability/)
- [CVE-2026-8794: PaperCut NG/MF Auth Bypass Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2026-8794/)
- [CVE-2026-8793 - PaperCut NG/MF: Insufficient brute-force protection](https://cvefeed.io/vuln/detail/CVE-2026-8793)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2178
