PaperCut NG and MF Zero-Day Exploitation Reported in the Wild
Active exploitation of vulnerability in print management software; advisory issued

Key Takeaways
- A zero-day vulnerability in PaperCut NG and PaperCut MF is being actively exploited in the wild.
- The flaw enables remote code execution via crafted HTTP requests on print management servers.
- No official patch is currently available; PaperCut has issued mitigations until a fix is released.
- Organizations are advised to segment networks, disable unnecessary services, and increase monitoring.
- The full technical details, CVE identifier, and affected version scope are pending official disclosure.
Quick answers
- What happened?
- PaperCut has warned that a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software is being actively exploited by threat actors in zero-day attacks. The flaw allows remote code execution via crafted HTTP requests, potentially leading to full system compromise. No patch is currently available, and the company has urged immediate network segmentation and monitoring.
- Which products are affected?
- PaperCut NG, PaperCut MF
- What should defenders do?
- PaperCut has recommended immediate network segmentation of Print servers, disabling unnecessary services, and enhancing monitoring for suspicious activity on Print management infrastructure. Organizations should apply the principle of least privilege and restrict network access to PaperCut servers until an official patch is released.
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. According to a security advisory published by the vendor, the flaw enables remote code execution through crafted HTTP requests directed at print management servers. The advisory notes that exploitation has been observed in the wild prior to full disclosure, and technical details of the vulnerability remain limited. PaperCut has stated that no official patch is available at the time of the advisory and has recommended that organizations immediately segment their PaperCut servers on isolated networks, disable unnecessary services, and monitor for suspicious activity. The company has attributed the exploitation to threat actors but has not named specific groups. The scope of affected versions and the full extent of the attack chain are still under investigation. BleepingComputer first reported on the advisory, noting that the lack of a timely fix increases the risk of ransomware delivery and unauthorized access to sensitive print infrastructure.
Security Details
The vulnerability allows remote code execution on PaperCut NG and PaperCut MF servers via crafted HTTP requests. Exploitation has been confirmed in the wild prior to full vendor disclosure. Technical details such as the CVE identifier and specific attack vector mechanics are not yet publicly disclosed. The flaw affects all versions of the software until a patch is released.
Affected products
PaperCut NG, PaperCut MF
Mitigation
PaperCut has recommended immediate network segmentation of Print servers, disabling unnecessary services, and enhancing monitoring for suspicious activity on Print management infrastructure. Organizations should apply the principle of least privilege and restrict network access to PaperCut servers until an official patch is released.
Sources
BleepingComputer
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Aug 27, 2026 · 16:31
Original link
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.




