PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assigned — Threadlinqs Intelligence
As of 2026-08-28, PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assigned is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-2179 · Severity: CRITICAL · Status: ACTIVE · Category: VULNERABILITY
PaperCut issued an urgent, technically sparse security bulletin on 27 Aug 2026 confirming active zero-day exploitation of a flaw in the web interface of PaperCut NG/MF's Application Server, with
On 27 August 2026, PaperCut Software published an urgent security bulletin stating it had confirmed customer incidents in which attackers exploited a then-undisclosed vulnerability in the web interface of the PaperCut NG/MF Application Server -- the central management component of both product lines -- to gain unauthenticated remote code execution and subsequently move deeper into victim networks. The company explicitly declined to publish technical root-cause details or a CVE identifier, citing the ongoing emergency, and stated every currently supported version of PaperCut NG and PaperCut MF is affected pending patching.
The issue was surfaced by a university customer whose internal security and digital-forensics teams detected active abuse and shared their findings with PaperCut; PaperCut's engineers reproduced the exploit from that information and confirmed in-the-wild abuse before publishing the bulletin, stating: "We are aware of confirmed customer incidents and are treating this matter with the highest priority." At 02:10 AEST on 28 August 2026 (13:20 ET on 27 August 2026), PaperCut released emergency, out-of-cycle, explicitly unvalidated builds for the v25 and v26 branches of both NG and MF (Windows, Linux, macOS): PaperCut MF 26.0.4.76494, PaperCut MF 25.0.12.76496, PaperCut NG 26.0.4.76495, and PaperCut NG 25.0.12.76497. A v24-branch build was still in progress at publication time. PaperCut framed these builds as a stopgap for administrators who cannot otherwise isolate a public-facing Application Server from the internet, not as the final, fully tested fix.
PaperCut's guidance identifies the attack surface as the Application Server's web interface when reachable from the public internet, and recommends organizations immediately restrict access to trusted internal IP addresses via firewall/ACL, or take the server offline entirely if that is not possible. For compromise hunting, PaperCut published artifacts observed in confirmed incidents: anomalous/suspicious activity -- including, per a recreated proof-of-concept, unexpected child processes -- originating from the legitimate pc-app.exe Application Server process; server.log files that are missing, truncated, modified, or deleted; the log string "ERROR No suitable driver found for jdbc:no:x"; and the log string "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST" (the cardID reference reflects PaperCut's card/ID-based print-release integration used heavily in the confirmed-affected education sector). PaperCut also pointed customers to alerts from intrusion-detection, endpoint-security, and network-monitoring tooling tied to the Application Server, and cautioned that the absence of the published artifacts does not rule out compromise; verified IOCs and remediation guidance were still being updated as the investigation continued.
No public source has attributed the 2026 campaign to a specific threat actor, malware family, or C2 infrastructure as of this writing; attribution confidence for this zero-day is accordingly LOW. The incident nonetheless lands on a product and attack surface with an extensively documented history of mass exploitation that illustrates the realistic post-exploitation trajectory PaperCut is now warning about. PaperCut's March 2023 unauthenticated RCE (CVE-2023-27350, CVSS 9.8, rooted in improper access control in the Application Server's 'SetupCompleted' Java class, reachable via the '/app' endpoint) and companion authentication-bypass/information-disclosure flaw (CVE-2023-27351) were both added to CISA's Known Exploited Vulnerabilities catalog. Per the FBI/CISA joint advisory AA23-131A (12 May 2023), the Bl00dy Ransomware Gang began exploiting CVE-2023-27350 in mid-April 2023 against internet-exposed PaperCut Application Servers concentrated in the U.S. Education Facilities Subsector -- which accounted for roughly 68% of exposed PaperCut servers at the time -- issuing commands through PaperCut's print-scripting interface to do
Target sectors: education
Timeline
- PaperCut patches CVE-2023-27350 (unauthenticated RCE, CVSS 9.8, via the Application Server's 'SetupCompleted' class) and CVE-2023-27351 (auth bypass/info disclosure) in the same Application Server component; both were later mass-exploited by multiple ransomware groups and state-sponsored actors.
- Threat actors register malicious C2 domains (windowservicecemter.com, anydeskupdate.com, netviewremote.com) later used to deliver TrueBot, DiceLoader, and Cobalt Strike Beacon payloads against PaperCut Application Servers vulnerable to CVE-2023-27350, per SecurityScorecard research.
- Per FBI-observed information cited in CISA advisory AA23-131A, the Bl00dy Ransomware Gang begins exploiting CVE-2023-27350 against internet-exposed PaperCut Application Servers concentrated in the U.S. Education Facilities Subsector.
- CISA and the FBI publish joint advisory AA23-131A confirming Bl00dy's education-sector PaperCut campaign: commands issued via PaperCut's print-scripting interface to download RMM software, Tor-proxied C2 traffic, and LockBit 3.0/Babuk/Conti-derived ransomware builders appending a '.bl00dy' extension.
- CISA re-adds CVE-2023-27351 to the Known Exploited Vulnerabilities catalog, signaling renewed active targeting of internet-exposed PaperCut infrastructure ahead of this new zero-day.
- Honeypot connections attempting to exploit CVE-2023-27350 are still being recorded, confirming internet-exposed PaperCut Application Servers remain a live target independent of the new flaw.
- A university customer's internal security and digital-forensics team detects active exploitation of an undisclosed PaperCut NG/MF web-interface flaw and shares findings with PaperCut.
- PaperCut engineers reproduce the exploit from the customer's findings and confirm in-the-wild abuse across multiple customer incidents.
- PaperCut publishes an urgent, technically sparse security bulletin confirming active zero-day exploitation and stating it is treating the matter with highest priority; no CVE or CVSS assigned.
- The Register, BleepingComputer, and other outlets publish the first public reporting on the active PaperCut NG/MF zero-day.
- PaperCut releases emergency, unvalidated, out-of-cycle builds at 02:10 AEST: NG/MF 25.0.12 and 26.0.4 branches for Windows, Linux, and macOS; the v24 build remains in progress.
- PaperCut urges customers with internet-facing Application Servers to immediately restrict web access to trusted IP addresses or take the server offline pending a fully validated fix.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1190, T1059.001, T1219, T1071.001, T1090.003, T1070.004, T1087, T1021, T1583.001