PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assigned
PaperCut NG/MF Application Server Zero-Day (TL-2026-2179), also tracked as PaperCut NG/MF August 2026 Zero-Day, is a critical-severity software vulnerability, first published 2026-08-28. It has no confirmed attribution, affects PaperCut Software Pty Ltd PaperCut NG, maps to 9 MITRE ATT&CK techniques (T1021, T1059.001, T1070.004), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2179
- Threat ID
- TL-2026-2179
- Also known as
- PaperCut NG/MF August 2026 Zero-Day, PaperCut Security Bulletin 27 Aug 2026
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-08-28
- Last reviewed
- 2026-08-28
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- education
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in PaperCut NG/MF Application Server Zero-Day
Malware and tooling: Lizar - S0681, Silence, Cobalt Strike
PaperCut issued an urgent, technically sparse security bulletin on 27 Aug 2026 confirming active zero-day exploitation of a flaw in the web interface of PaperCut NG/MF's Application Server, with confirmed customer breaches and lateral movement into victim networks. No CVE or CVSS has been assigned; PaperCut shipped unvalidated, out-of-cycle emergency builds (NG/MF v25.0.12 and v26.0.4) on 28 Aug 2026 while root-cause analysis continues.
How PaperCut NG/MF Application Server Zero-Day works
On 27 August 2026, PaperCut Software published an urgent security bulletin stating it had confirmed customer incidents in which attackers exploited a then-undisclosed vulnerability in the web interface of the PaperCut NG/MF Application Server -- the central management component of both product lines -- to gain unauthenticated remote code execution and subsequently move deeper into victim networks. The company explicitly declined to publish technical root-cause details or a CVE identifier, citing the ongoing emergency, and stated every currently supported version of PaperCut NG and PaperCut MF is affected pending patching.
The issue was surfaced by a university customer whose internal security and digital-forensics teams detected active abuse and shared their findings with PaperCut; PaperCut's engineers reproduced the exploit from that information and confirmed in-the-wild abuse before publishing the bulletin, stating: "We are aware of confirmed customer incidents and are treating this matter with the highest priority." At 02:10 AEST on 28 August 2026 (13:20 ET on 27 August 2026), PaperCut released emergency, out-of-cycle, explicitly unvalidated builds for the v25 and v26 branches of both NG and MF (Windows, Linux, macOS): PaperCut MF 26.0.4.76494, PaperCut MF 25.0.12.76496, PaperCut NG 26.0.4.76495, and PaperCut NG 25.0.12.76497. A v24-branch build was still in progress at publication time. PaperCut framed these builds as a stopgap for administrators who cannot otherwise isolate a public-facing Application Server from the internet, not as the final, fully tested fix.
PaperCut's guidance identifies the attack surface as the Application Server's web interface when reachable from the public internet, and recommends organizations immediately restrict access to trusted internal IP addresses via firewall/ACL, or take the server offline entirely if that is not possible. For compromise hunting, PaperCut published artifacts observed in confirmed incidents: anomalous/suspicious activity -- including, per a recreated proof-of-concept, unexpected child processes -- originating from the legitimate pc-app.exe Application Server process; server.log files that are missing, truncated, modified, or deleted; the log string "ERROR No suitable driver found for jdbc:no:x"; and the log string "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST" (the cardID reference reflects PaperCut's card/ID-based print-release integration used heavily in the confirmed-affected education sector). PaperCut also pointed customers to alerts from intrusion-detection, endpoint-security, and network-monitoring tooling tied to the Application Server, and cautioned that the absence of the published artifacts does not rule out compromise; verified IOCs and remediation guidance were still being updated as the investigation continued.
No public source has attributed the 2026 campaign to a specific threat actor, malware family, or C2 infrastructure as of this writing; attribution confidence for this zero-day is accordingly LOW. The incident nonetheless lands on a product and attack surface with an extensively documented history of mass exploitation that illustrates the realistic post-exploitation trajectory PaperCut is now warning about. PaperCut's March 2023 unauthenticated RCE (CVE-2023-27350, CVSS 9.8, rooted in improper access control in the Application Server's 'SetupCompleted' Java class, reachable via the '/app' endpoint) and companion authentication-bypass/information-disclosure flaw (CVE-2023-27351) were both added to CISA's Known Exploited Vulnerabilities catalog. Per the FBI/CISA joint advisory AA23-131A (12 May 2023), the Bl00dy Ransomware Gang began exploiting CVE-2023-27350 in mid-April 2023 against internet-exposed PaperCut Application Servers concentrated in the U.S. Education Facilities Subsector -- which accounted for roughly 68% of exposed PaperCut servers at the time -- issuing commands through PaperCut's print-scripting interface to download and execute legitimate remote-management-and-maintenance (RMM) software, masking C2 traffic through Tor and other proxies, and in some intrusions exfiltrating data before encrypting victim systems with LockBit 3.0-, Babuk-, and Conti-derived ransomware builders that appended a '.bl00dy' file extension. In parallel, the Lace Tempest cluster (a Cl0p ransomware affiliate) and separate LockBit RaaS affiliates independently weaponized the same CVE-2023-27350 flaw, staging malicious domains -- windowservicecemter.com, anydeskupdate.com, and netviewremote.com, registered 12 April 2023 -- to deliver TrueBot and DiceLoader loaders and Cobalt Strike Beacons for follow-on data theft and ransomware deployment, per SecurityScorecard's contemporaneous research. Microsoft separately reported Iranian state-sponsored clusters tracked as Mint Sandstorm and Mango Sandstorm also exploiting the same PaperCut flaw. CVE-2023-27351 was re-added to the KEV catalog on 20 April 2026, and honeypot exploitation attempts against CVE-2023-27350 were still being recorded as recently as 19 July 2026 -- confirming that internet-exposed PaperCut Application Server infrastructure remains an active, recurring, multi-actor target independent of this new zero-day, and that the 'moving deeper into networks' behavior PaperCut describes for the 2026 incidents matches a well-precedented playbook on this exact attack surface.
MITRE ATT&CK techniques used in TL-2026-2179
Lateral Movement
Execution
Defense Evasion
T1070.004 Indicator Removal: File Deletion
Command and Control
T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1219 Remote Access Tools
Discovery
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Affected products and versions in PaperCut NG/MF Application Server Zero-Day
- PaperCut Software Pty Ltd — PaperCut NG
Vulnerable versions: all currently supported versions prior to the 28 Aug 2026 emergency build
Fixed in: 25.0.12.76497; 26.0.4.76495 - PaperCut Software Pty Ltd — PaperCut MF
Vulnerable versions: all currently supported versions prior to the 28 Aug 2026 emergency build
Fixed in: 25.0.12.76496; 26.0.4.76494
Remediation for PaperCut NG/MF Application Server Zero-Day
Patches
- PaperCut MF v26: 26.0.4.76494 (emergency, unvalidated, out-of-cycle build, released 28 Aug 2026 02:10 AEST)
- PaperCut MF v25: 25.0.12.76496 (emergency, unvalidated, out-of-cycle build, released 28 Aug 2026 02:10 AEST)
- PaperCut NG v26: 26.0.4.76495 (emergency, unvalidated, out-of-cycle build, released 28 Aug 2026 02:10 AEST)
- PaperCut NG v25: 25.0.12.76497 (emergency, unvalidated, out-of-cycle build, released 28 Aug 2026 02:10 AEST)
- PaperCut v24-branch build still in development as of 28 Aug 2026
Immediate actions
- Restrict PaperCut NG/MF Application Server web-interface access to trusted internal IP addresses only, via firewall rules or network access controls
- If the Application Server cannot be isolated from the internet, apply PaperCut's emergency out-of-cycle build immediately: NG/MF v25.0.12 or v26.0.4 (v24 build pending)
- Hunt for compromise indicators: anomalous pc-app.exe activity (including unexpected child processes), missing/truncated/deleted server.log files, and the documented 'jdbc:no:x' and 'DatabaseUtils - ... cardID' log error strings
- Treat any Application Server that was internet-facing prior to the 27 Aug 2026 advisory and not immediately isolated as potentially compromised, even absent the listed IOC artifacts
- Review IDS, EDR, and network-monitoring alerts tied to the PaperCut Application Server process for the weeks preceding detection, given the precedent of RMM-software abuse and Tor-proxied C2 traffic on this same attack surface
Workarounds
- Take the PaperCut Application Server fully offline (disconnect from the internet) if it cannot be restricted to trusted IPs and the emergency patch cannot be applied immediately
- Block all inbound internet access to the Application Server's web-interface ports at the perimeter firewall pending patching
Longer-term hardening
- Never expose the PaperCut Application Server web interface directly to the public internet; place it behind a VPN, reverse proxy, or zero-trust access gateway
- Apply PaperCut's validated, non-emergency patch once released, and re-verify the emergency build for stability and completeness of the fix
- Deploy EDR and network monitoring with alerting tuned to PaperCut Application Server process anomalies (including LOLBin child processes of pc-app.exe such as powershell.exe, cmd.exe, mshta.exe, rundll32.exe), given the product's repeated history as an initial-access and ransomware vector (CVE-2023-27350/27351)
Timeline of PaperCut NG/MF Application Server Zero-Day
- PaperCut patches CVE-2023-27350 (unauthenticated RCE, CVSS 9.8, via the Application Server's 'SetupCompleted' class) and CVE-2023-27351 (auth bypass/info disclosure) in the same Application Server component; both were later mass-exploited by multiple ransomware groups and state-sponsored actors.
- Threat actors register malicious C2 domains (windowservicecemter.com, anydeskupdate.com, netviewremote.com) later used to deliver TrueBot, DiceLoader, and Cobalt Strike Beacon payloads against PaperCut Application Servers vulnerable to CVE-2023-27350, per SecurityScorecard research.
- Per FBI-observed information cited in CISA advisory AA23-131A, the Bl00dy Ransomware Gang begins exploiting CVE-2023-27350 against internet-exposed PaperCut Application Servers concentrated in the U.S. Education Facilities Subsector.
- CISA and the FBI publish joint advisory AA23-131A confirming Bl00dy's education-sector PaperCut campaign: commands issued via PaperCut's print-scripting interface to download RMM software, Tor-proxied C2 traffic, and LockBit 3.0/Babuk/Conti-derived ransomware builders appending a '.bl00dy' extension.
- CISA re-adds CVE-2023-27351 to the Known Exploited Vulnerabilities catalog, signaling renewed active targeting of internet-exposed PaperCut infrastructure ahead of this new zero-day.
- Honeypot connections attempting to exploit CVE-2023-27350 are still being recorded, confirming internet-exposed PaperCut Application Servers remain a live target independent of the new flaw.
- The Register, BleepingComputer, and other outlets publish the first public reporting on the active PaperCut NG/MF zero-day.
- PaperCut publishes an urgent, technically sparse security bulletin confirming active zero-day exploitation and stating it is treating the matter with highest priority; no CVE or CVSS assigned.
- PaperCut engineers reproduce the exploit from the customer's findings and confirm in-the-wild abuse across multiple customer incidents.
- A university customer's internal security and digital-forensics team detects active exploitation of an undisclosed PaperCut NG/MF web-interface flaw and shares findings with PaperCut.
- PaperCut urges customers with internet-facing Application Servers to immediately restrict web access to trusted IP addresses or take the server offline pending a fully validated fix.
- PaperCut releases emergency, unvalidated, out-of-cycle builds at 02:10 AEST: NG/MF 25.0.12 and 26.0.4 branches for Windows, Linux, and macOS; the v24 build remains in progress.
Sources cited for PaperCut NG/MF Application Server Zero-Day
- PaperCut warns of NG, MF flaw exploited in zero-day attacks
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
- PaperCut warns of NG, MF flaw exploited in zero-day attacks
- Unknown PaperCut NG/MF vulnerability is under active attack
- PaperCut NG/MF Vulnerability Actively Exploited in Attack - All Versions Impacted
- PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers
- PaperCut Software: Unknown PaperCut NG/MF vulnerability is under active attack
- Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG (AA23-131A)
- CISA Adds Eight Known Exploited Vulnerabilities to Catalog
- PaperCut Vulnerability PoC Released
- Ransomware Affiliates Exploit Recently-Discovered PaperCut Vulnerability
- CISA warns of Bl00dy ransomware gang using PaperCut vulnerability to attack schools
- PaperCut MF/NG Potential Exploitation (Sigma rule)
More in vulnerability
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
Detection coverage for TL-2026-2179
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2179 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.