PaperCut NG/MFPaperCut

Attackers exploit zero-day in PaperCut NG/MF print software, affecting all versions; fixed v25 and v26 released, v24 to follow

Attackers are exploiting a zero-day vulnerability in all versions of PaperCut NG/MF print management software, prompting the release of emergency patches for versions 25 and 26, with version 24 to follow. The extent of the attacks and details of the vulnerability remain unclear, raising urgent security concerns.

heise online heise online+1 source28 August 2026 · 11:43 UTC
CuriousCats Full Story

Attackers are exploiting a zero-day vulnerability in all versions of PaperCut NG/MF print management software, leading to emergency patches for versions 25 and 26, with version 24 expected to follow. The developers have issued urgent warnings, stating they are aware of confirmed customer incidents and are treating the matter with the highest priority.12

Currently, there is no CVE number for the vulnerability, and the specifics of the flaw remain undisclosed. The extent of the attacks is unknown, and it is unclear what actions attackers can take after a successful breach. The developers have provided initial indicators of compromise (IoCs) to help admins identify affected systems, but they caution that systems may still be compromised even if no IoCs are detected.38

Admins are advised to restrict access to the PaperCut Application Server, especially for those exposed to the internet, by implementing firewall rules and network access controls. PaperCut emphasized, "Take this action now, even if you have not observed suspicious activity." The company is conducting an ongoing investigation into the incident and plans to update the warning message with more IoCs.79

In 2023, a previous vulnerability in PaperCut MF and NG was exploited by Russian threat actors and a financially motivated group to deliver ransomware, highlighting the ongoing risks associated with this software.

Key Insight
“The developers have provided initial Indicators of Compromise, including suspicious activity around pc-app.exe and specific log errors, but warn that systems may still be compromised even if none are found. Admins are advised to apply firewall rules restricting access to trusted devices if instances are publicly accessible.”
CuriousCats studied:
1
heise onlineheise online
“Currently, attackers are targeting a security vulnerability in PaperCut NG/MF. There is no concrete information about the vulnerability yet. Versions secured against attacks are available for download.”
heise online →
2
The Hacker NewsThe Hacker News
“PaperCut has customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.”
The Hacker News →
Ask CuriousCats
What is PaperCut NG/MF software?
Who discovered the zero-day vulnerability?
Why are firewall rules recommended for admins?
How does this vulnerability impact other software?
Which versions are now deemed secure?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats