ELSEIF
Your brief EB
446 stories from 139 feeds 682 clusters Refreshed 11 minutes ago next pull 02:44

SECURITY Signal 424

PaperCut warns of active zero-day exploitation across all NG and MF print server versions

PaperCut disclosed that attackers are actively exploiting a previously undisclosed vulnerability in every version of PaperCut NG and PaperCut MF, with confirmed customer incidents, and released emergency patches for internet-exposed Application Servers.

WHY IT MATTERS

Only one feed carried this story, so corroboration is limited. Administrators running internet-facing PaperCut Application Servers need to immediately restrict access and apply emergency patches, as the vulnerability affects all versions and active exploitation is confirmed. The absence of a CVE, technical details, or attacker attribution means defenders cannot yet fully scope the risk.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

PaperCut confirmed active exploitation of a previously undisclosed vulnerability affecting all versions of PaperCut NG and PaperCut MF.

02

Emergency patches are available for public-facing Application Servers, but PaperCut has not published a CVE or technical details of the flaw.

03

Indicators of compromise include suspicious pc-app.exe activity and modified or missing server.log files, but absence of these signs does not rule out compromise.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

PaperCut published a security advisory on August 27, 2026, warning that attackers are actively exploiting a previously undisclosed vulnerability in every version of PaperCut NG and PaperCut MF. The company has confirmed incidents at customer organizations but has not released a CVE, a technical description of the flaw, the attack chain, or any attribution. The immediate risk is concentrated in organizations with internet-exposed PaperCut Application Servers, and PaperCut urges administrators to restrict access to the products' web interfaces using firewall rules or network access controls, allowing connections only from trusted IP addresses.

PaperCut has released emergency patches for customers with public-facing NG or MF Application Servers who cannot take other mitigating action. The advisory does not establish that the emergency fixes are a complete replacement for normal remediation across all deployments, so organizations should apply the fixes appropriate to their installation while keeping external access restricted. The cost of adoption is therefore twofold: applying the patch and reconfiguring network access to remove public exposure, which may require coordination across firewall, network, and application teams.

PaperCut provided indicators that may help defenders identify compromise, including reviewing activity involving the legitimate pc-app.exe process and checking whether server.log files have been modified, deleted, or missing. The company also flagged specific error messages to look for in server.log, including an error about no suitable driver found for jdbc:no:x and a DatabaseUtils error looking up cardID. However, PaperCut explicitly warns that a server without any of the listed signs may still have been compromised, making these indicators useful for triage but insufficient to clear a server.

The operational impact remains unresolved because PaperCut has not described what attackers do after gaining access, whether they can move laterally from a print server into the wider network, or whether customer data is being stolen. The company has not said whether the campaign is focused on ransomware, credential theft, network access, document archives, or another objective. PaperCut's history is relevant context: in April 2023, attackers exploited CVE-2023-27350, a critical authentication bypass that allowed unauthenticated remote code execution, with intrusions linked to Clop and LockBit ransomware operations, Iranian state-backed groups, and the Bl00dy ransomware gang targeting the education sector. However, PaperCut has not attributed the 2026 attacks to the same actors or objectives, so defenders should not assume continuity with the prior campaign.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
for(geeks) PaperCut warns of active zero-day attacks on print servers Open ↗