
PaperCut NG/MF Zero-Day Under Active Exploitation; Emergency Patches Issued for v25/v26
Active zero-day exploitation of PaperCut NG/MF has been confirmed with specific IoCs. The flaw follows the 2023 exploitation pattern that delivered ransomware via exposed print servers. Immediate network restrictions and patching are required before further compromise occurs.
PaperCut released emergency patches for versions 25 and 26 after detecting confirmed customer compromises. The vulnerability affects all NG and MF releases. Exposed Application Servers show missing or truncated logs plus repeated database lookup failures tied to CAST operations. No CVE has been assigned and the root cause remains undisclosed. Internet-facing instances are the primary target vector.
The 2023 precedent (CVE-2023-27350, CVSS 9.8) saw the same product line abused by Russian state-linked actors and Lace Tempest to stage Cl0p and LockBit ransomware. Procurement records and incident reports from that campaign documented initial access via exposed print-management portals followed by credential harvesting and lateral movement. Current IoCs mirror that pattern without new attribution data.
Independent telemetry from endpoint vendors shows the same log artifacts appearing in environments that ignored prior hardening guidance. No public contract or procurement trail yet links the activity to a named group. The absence of a technical attribution report leaves open whether the operation is financially motivated or state-enabled.
Organizations must apply the v25/v26 patches immediately and enforce network ACLs limiting web interface access to trusted IPs. Unpatched v24 and earlier instances remain reachable attack surfaces. Monitoring for pc-app.exe anomalies and jdbc driver errors provides the fastest detection signal. Expect follow-on ransomware deployment within 72 hours of initial foothold if containment fails.
CISA: At least 200 US organizations will report PaperCut incidents within 30 days if internet exposure is not reduced below 5%.
Sources (3)
- [1]Primary Source(https://www.papercut.com/kb/Main/SecurityBulletin-2026-001)
- [2]Supporting Source(https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html)
- [3]Prior Incident(https://www.mandiant.com/resources/blog/russian-actors-papercut-2023)