TL;DR
PaperCut confirmed a NG/MF vulnerability exploited in the wild on 27 August 2026. The flaw affects all versions of PaperCut NG and PaperCut MF. The vendor shipped an emergency patch and urged admins to restrict public access at once.
Why It Matters
PaperCut runs print management for schools, offices, and government. One source estimates deployment across roughly 70,000 organizations and 100 million users. That reach makes any PaperCut NG/MF vulnerability exploited in the wild a broad ransomware risk. Attackers have a long history with this software. Clop, LockBit, and Bl00dy affiliates all abused earlier bugs like CVE-2023-27350 and CVE-2023-27351 for initial access.
How the Attack Works
PaperCut has not disclosed the technical root cause. The advisory points to a remotely reachable flaw in the Application Server web interface. In its bulletin, PaperCut says it is “investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.” A university customer’s forensics team helped the vendor reproduce the bug. No exploit code is published here.
Affected Versions
The advisory applies to all versions of PaperCut NG and PaperCut MF. Emergency builds cover the v25 and v26 branches on Windows, Linux, and macOS. A fix for the older v24 branch is still in progress.
Patch and Mitigation
Apply the emergency patch first. Then restrict the server. As the vendor warns, “immediately restrict web access to trusted IP addresses only.” Take this step even without signs of intrusion. Watch server.log for suspicious database errors and missing entries.
Exploitation Status
PaperCut confirms active exploitation and “confirmed customer incidents.” No CVE identifier has been assigned yet. The vendor says it will publish validated indicators of compromise as they become available.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!