A severe new vulnerability in PaperCut NG and MF print management software is being actively exploited, prompting the vendor to issue emergency patches and urgent warnings on August 27, 2026. The weakness affects every currently supported version of both products, making updates essential for all users.
What We Know So Far
PaperCut’s security team confirmed confirmed attacks stemming from an as-yet-unidentified flaw in its Application Server component. Evidence emerged when a university customer flagged suspicious behavior, enabling engineers to replicate the bug and confirm real-world exploitation. While the root cause remains undisclosed, the situation is serious: the vendor describes the path of attack as likely remote exploitation on servers exposed to the internet.
Mitigation and Patching
Administrators whose PaperCut Application Server is publicly reachable are being instructed to immediately limit access to trusted IP ranges such as internal networks, or else use equivalent firewall or network policies. Silence or normal log behavior so far does not guarantee safety—any discrepancy might mean breach activity is hiding.
Signs of possible compromise include strange behavior by the pc-app.exe process, missing or truncated server.log files, and specific error messages like “ERROR No suitable driver found for jdbc:no:x” or “ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST”.
Emergency Patch Rollout
By 2:10 a.m. AEST on August 28, 2026, PaperCut released out-of-cycle emergency builds for NG/MF version 25 and 26, covering Windows, Linux, and macOS installers. These patches are only intended for systems accessible via the public internet. An update for version 24 is still in progress. Users are urged to upgrade to the latest version wherever possible.
Background & Why This Matters
This isn’t the first time PaperCut’s print software has been a target. In 2023, a flaw that allowed authentication bypass—CVE-2023-27351—was abused by ransomware groups. That vulnerability also made its way into CISA’s catalog of known exploited vulnerabilities, underscoring the company’s heightened profile among attackers.
With this new flaw already being used in attacks, researchers worry that scanning tools and opportunistic threat actors will quickly begin probing for exposed PaperCut servers. The combination of urgent patches, existing exposure, and past attacks raises the stakes considerably.
What to Watch For: keep an eye on whether PaperCut publishes detailed indicators of compromise so teams can detect post-infiltration activity. Also, observe how organizations balance network segmentation, firewall rules, and patching speed—these will be the front lines in containing exploit spread.
Analysis: This vulnerability highlights a recurring challenge: systems once considered internal can become high-risk once they're internet-facing. PaperCut’s emergency build signals the severity and immediacy of the threat — swift patching isn't optional. For companies using print-management workflows, this event could prompt reassessment of architecture and exposure risk. Going forward, expect attention from both attackers and oversight agencies demanding proof of remediation.