Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
PaperCut Software confirmed on August 27, 2026, the active zero-day exploitation of an undisclosed vulnerability affecting all versions of PaperCut NG and PaperCut MF. The vendor is aware of confirmed customer incidents and has classified the incident as highest priority, releasing emergency patches for internet-exposed servers. The lack of a CVE identifier and complete technical details makes mitigation difficult for organizations that cannot immediately isolate their systems.
- PaperCut confirmed active zero-day exploitation across all versions of PaperCut NG and PaperCut MF, with verified customer incidents
- The security team reproduced the vulnerability using information provided by a university-sector customer, but has not yet disclosed the technical mechanism
- The only known indicators of compromise (IoCs) involve anomalies in the pc-app.exe process, alterations to the server.log file, and a specific database log error
- The vendor recommends restricting web access to trusted IP addresses, but has not disclosed patched versions or details on the fix
A Zero-Day Reproduced In-House, Without CVE or Public Vector
PaperCut's security response team successfully reproduced the vulnerability internally, leveraging information provided by a university-sector customer. This is significant: reproducibility confirms the flaw's real danger, yet the vendor has chosen not to publicly disclose either the vulnerability class or the exploitation mechanism. The absence of a CVE identifier and CVSS score prevents organizations from plugging the threat into standard risk-scoring frameworks.
Primary sources agree the vulnerability is remotely exploitable on publicly exposed servers. HelpNetSecurity reports PaperCut's direct recommendation: "If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only." The same source highlights that internet exposure is the determining risk factor, not a specific misconfiguration or outdated version.
The vendor has released what it defines as emergency patches, but has not communicated which versions incorporate them or whether they are available through the standard automatic update channel. This operational opacity forces system administrators to contact PaperCut support directly to verify the status of their systems.
The Known IoCs: Three Compromise Signals to Monitor
PaperCut provided a small but specific set of indicators of compromise, cited by both primary sources. The first concerns suspicious activity from the legitimate pc-app.exe process: anomalous execution of the Application Server's main binary that could indicate exploitation followed by code execution in the process context. The second is the modification, deletion, or absence of the server.log file, suggesting threat actors' attempts to cover their tracks.
The third indicator is a specific database error: ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST. This string in logs may reflect injection attempts or manipulation of internal application parameters. PaperCut explicitly warned that the absence of these IoCs does not rule out compromise, widening the uncertainty perimeter for threat-hunting operations.
Neither the threat actors' identities nor observed post-compromise activities have been disclosed. The dossier does not specify whether attacks involved data theft, ransomware deployment, or persistent access to victim networks.
The 2023 Precedent: Authentication Bypass, RCE, and Ransomware Escalation
The 2026 zero-day revives a pattern observed in March–April 2023, when PaperCut faced massive exploitation via two cataloged vulnerabilities: CVE-2023-27350 (CVSS 9.8, CRITICAL) and CVE-2023-27351. According to Trend Micro's advisory, the first was an improper access control authentication bypass requiring no authentication and leading to Remote Code Execution.
Advisories ZDI-23-233 and ZDI-23-232, published with coordinated release on March 14, 2023, identified the flaws respectively in the SetupCompleted class and the SecurityRequestFilter. Advisory ZDI-23-233 specified that an attacker could bypass authentication and execute arbitrary code in the context of SYSTEM. In subsequent weeks, per historical HelpNetSecurity reports, exploitation was attributed to ransomware groups including Clop and LockBit, as well as Iranian APT actors and the Bl00dy Ransomware Gang.
These historical details are relevant as context, but must not be overlaid onto the 2026 zero-day: PaperCut has indicated no technical correlations between the new vulnerability and the previous CVE-2023-27350/27351, nor released information allowing such links to be established independently.
"PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority."
Immediate Actions
- Restrict web access to the Application Server to trusted IP addresses via firewall rules or network access controls, as explicitly recommended by PaperCut via HelpNetSecurity
- Check for documented IoCs in your environment: anomalies in the pc-app.exe process, integrity of the server.log file, presence of the DatabaseUtils cardID error in logs
- Contact PaperCut support to obtain emergency patches and confirm whether installed versions are covered by corrective releases
- Assess internet exposure of all PaperCut NG/MF instances, including servers in perimeter network segments or with guest VPN access
A Cycle That Questions the Security Development Lifecycle
The recurrence of massive exploitation on PaperCut — with an interval of just over three years between the 2023 cycle and the 2026 zero-day — raises questions about the maturity of the vendor's security development lifecycle. The fact that the new vulnerability affects all versions, with no declared exceptions, points to a possible architectural regression or an attack surface insufficiently reduced after previous incidents.
The persistence of internet-exposed print management systems, often treated as secondary infrastructure in enterprise risk assessments, amplifies the impact. PaperCut itself identified public visibility as a necessary condition for exploitation, not merely an aggravating factor. For organizations unable to isolate servers, the lack of technical details turns response into an exercise in uncertainty management rather than verified containment.
Comparison with 2023 suggests escalation velocity can be rapid: the previous CVEs saw public PoC publication, adoption by ransomware-as-a-service, and inclusion on the CISA KEV list within weeks. While this historical dynamic does not constitute predictive evidence for the current zero-day, the convergence of factors — software widely deployed in education and enterprise, frequent internet exposure, reproducible exploitation mechanism — configures a risk profile that standard perimeter defenses do not mitigate on their own.
Frequently Asked Questions
Why hasn't PaperCut assigned a CVE to the vulnerability?
The vendor has not yet disclosed a CVE identifier nor explained the delay in publication. It is common practice for a CVE to be requested or made public after initial patch release, but the absence of official communication on the matter remains a documented gap in the dossier.
Does the emergency patch fix all versions or only recent ones?
The dossier does not specify which versions receive the emergency patch. PaperCut stated the vulnerability affects all versions of PaperCut NG and MF, but has not published a list of corrected releases. Administrators must verify directly with the vendor.
Are the 2023 indicators useful for detecting the 2026 zero-day?
The IoCs provided for the 2026 zero-day are specific and distinct from the exploitation patterns documented in 2023. PaperCut warned that the absence of known IoCs does not rule out compromise, rendering any detection strategy based solely on historical rules ineffective.
Sources
- https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/
- https://www.helpnetsecurity.com/2026/08/27/papercut-ng-mf-vulnerability-attack/
- https://www.infosecurity-magazine.com/news/australia-exploitation-teamcity/
- https://www.papercut.com/kb/Main/PO-1216-and-PO-1219/
- https://success.trendmicro.com/en-US/solution/KA-0014401
- https://www.armis.com/blog/breaking-down-cisas-top-routinely-exploited-vulnerabilities/
- https://www.zerodayinitiative.com/advisories/ZDI-23-233/
- https://www.zerodayinitiative.com/advisories/ZDI-23-232/
- https://www.helpnetsecurity.com/2023/04/27/papercut-lockbit-clop/
- https://www.helpnetsecurity.com/2023/04/25/cve-2023-27350-poc/
Information verified against cited sources and current as of publication.
Fonti
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.