PaperCut Warns of NG, MF Flaw Exploited in Zero-Day Attacks
PaperCut said it has confirmed customer incidents and urged users with public-facing servers to apply an emergency patch or take systems offline.
- PaperCut Software issued an urgent security advisory on Thursday confirming active exploitation of a vulnerability in its NG and MF print management products affecting public-facing servers.
- The flaw affects public-facing Application Servers; administrators can mitigate risk by moving web interfaces off the public internet and restricting access to trusted internal addresses only.
- PaperCut released emergency patch builds on August 27, 2026 for Windows and Linux systems, cautioning that "We have not gone through our usual release process," according to the FAQ.
- Threat intelligence firm Huntress reported limited exploitation across customer environments, with attackers running basic commands to identify compromised systems and user accounts.
- Fashioning a permanent fix is ongoing; communicating technical details remains difficult to avoid attracting additional attackers, but PaperCut will advise customers once a better solution lands.
18 Articles
18 Articles
PaperCut Zero-Day Exploit: NG, MF Vulnerability Warning
Active Exploitation Warning: PaperCut has confirmed a zero-day vulnerability in NG and MF software allowing unauthenticated remote Java code execution. Emergency Remediation: Priority patches are available for versions 25 and 26, while administrators are advised to restrict public internet access to Application Server interfaces. Active Zero-Day Attacks Target Print Management PaperCut issued an urgent security advisory on August 27, 2026, warni…
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such attacks are the risk to which users of PaperCut print management software find themselves exposed today, after the company revealed a university’s security teams alerted it to an attack. The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut…
Multiple vulnerabilities have been discovered in Papercut. They allow an attacker to bypass authentication and execute arbitrary code remotely. Papercut indicates that these vulnerabilities are actively exploited. The editor explains that the patch blocks requests... See online: https://www.cert.ssi.gouv.fr/avis/C...
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











