In a significant cybersecurity incident, PaperCut has confirmed active exploitation of a vulnerability in its NG and MF print management software. In response, the company has swiftly issued an emergency patch, just hours after initially alerting users to the threat.
Immediate Action Required for PaperCut Users
The Australian software provider’s security team is deeply engaged in investigating confirmed incidents reported by customers. Although a formal CVE identifier has yet to be assigned, the company is prioritizing this issue. PaperCut’s security bulletin reveals that all currently supported versions of NG and MF are affected, making it imperative for users to act regardless of their specific version.
The vulnerability was brought to light by a university customer whose internal security team collaborated with PaperCut engineers. This collaboration allowed for the replication and confirmation of the exploit being actively used in real-world scenarios.
Technical Details and Security Recommendations
While technical specifics of the vulnerability remain undisclosed, the urgency of the company’s response, including a same-day emergency build, underscores the seriousness of this remote exploitation threat, particularly for internet-facing servers.
PaperCut advises all users with publicly accessible Application Servers to immediately restrict access to trusted IP ranges using firewall rules or similar network controls, even if no suspicious activity has been detected. This proactive measure is crucial to safeguarding systems.
Organizations should also scrutinize systems for potential compromise signs. Indicators include anomalies originating from the pc-app.exe process, abnormalities in server.log files, and specific error messages. However, absence of these signs does not guarantee system safety, and PaperCut intends to provide validated compromise indicators as the investigation progresses.
Urgent Software Update and Historical Context
Early on August 28, 2026, PaperCut released emergency updates for the NG and MF v25 and v26 branches across Windows, Linux, and macOS. These emergency builds are targeted at administrators managing public-facing servers that cannot be isolated from the internet. A build for the older v24 is forthcoming, and users are strongly encouraged to update to the latest versions where possible.
This incident echoes past vulnerabilities within PaperCut’s platform, such as the 2023 authentication bypass flaw, CVE-2023-27351, previously exploited by ransomware groups and listed in CISA’s Known Exploited Vulnerabilities catalog. This history suggests that the current flaw will likely attract further attention from malicious actors, emphasizing the necessity for prompt patching and network segmentation.
The swift action by organizations in updating their systems and reinforcing network defenses is crucial to mitigating potential breaches and ensuring ongoing security.
