Skip to main content
Emerging ThreatsMalware & Ransomware

PaperCut Zero-Day Vulnerability Exploited in Active Attacks

Office computer monitor displays print management software interface surrounded by office equipment.

"We are aware of confirmed customer incidents and are treating this matter with the highest priority," PaperCut said, notifying customers that bad actors are actively exploiting a vulnerability in its software.

PaperCut alert: scope and immediate posture

PaperCut has warned that a zero‑day vulnerability is being actively exploited in attacks against all versions of its PaperCut NG and PaperCut MF print management software. The company says it has identified confirmed customer incidents and has opened an investigation that is ongoing. Beyond acknowledging exploitation, PaperCut has not published technical details about the flaw, how it is being exploited, or who is responsible.

Emergency patch released for v25 and v26

To address the active exploitation, PaperCut released an emergency patch for versions v25 and v26 of the software. The company has urged customers to apply mitigations immediately while the investigation continues. There are no additional published patches for other versions at this time in the advisory PaperCut issued.

Observed indicators of compromise

PaperCut provided a short list of indicators of compromise (IOCs) that organizations can use to triage affected systems. These include:

  • Alerts from intrusion‑detection, endpoint‑security, or network‑monitoring tools that reference the PaperCut Application Server, with particular attention to suspicious post‑exploitation activity from "pc-app.exe".
  • Missing, unexpectedly truncated, or deleted PaperCut server.log files.
  • The presence of the following entries in server.log: "ERROR No suitable driver found for jdbc:no:x" and "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST".

Immediate mitigation: restrict internet exposure and apply network controls

PaperCut advises that any PaperCut NG/MF Application Server exposed to the internet should be immediately restricted to trusted IP addresses. The company recommended specific measures: "Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses." PaperCut added a pointed urging: "Take this action now, even if you have not observed suspicious activity."

How security teams, IT leaders, and end users are likely to respond

  • Security teams: Will use the published indicators—pc-app.exe alerts, missing or truncated server.log files, and the two server.log error entries—to search logs and detection tooling for signs of compromise while applying network restrictions and the v25/v26 patch where applicable.
  • IT and procurement leaders at affected organizations: Must prioritize limiting internet exposure for PaperCut Application Servers and coordinate patching for v25 and v26 installs; they will also review whether older or custom deployments can be safely taken offline, segmented, or otherwise protected until further fixes are available.
  • End users and print operators: Should expect possible service interruptions as administrators restrict access or apply mitigations; they will also need clear communication from IT about changes to printing workflows while servers are contained and investigated.

The advisory invokes a recent precedent. In 2023, a critical flaw in PaperCut MF and NG (CVE‑2023‑27350, CVSS score: 9.8) was exploited by Russian threat actors and a financially motivated group called Lace Tempest to deliver Cl0p and LockBit ransomware. PaperCut’s current notice does not connect the present exploit to that earlier campaign, and the company explicitly states there are no public details yet on exploitation technique or attribution for this incident.

This is a developing story: PaperCut has released a patch for two recent versions and issued immediate containment guidance, but key technical and attribution details remain unreleased. Will PaperCut and investigators publish the vulnerability’s technical root cause, exploitation chain, and any forensic indicators beyond the short list already released? For organizations running PaperCut NG or MF, the concrete actions are clear—restrict internet access to the Application Server now, apply the v25/v26 emergency patch where relevant, and hunt for the specific server.log entries and tampering indicators that PaperCut has identified.

Source: https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html