• 3 min read
PaperCut warns of active zero-day attacks on print servers
PaperCut says attackers are exploiting a flaw in all NG and MF versions and urges exposed customers to restrict access and install emergency patches.

Image: BleepingComputer
PaperCut is warning that attackers are actively exploiting a previously undisclosed vulnerability in every version of PaperCut NG and PaperCut MF. The company says it has confirmed incidents at customer organizations but has not yet disclosed the flaw’s technical details, attack chain, or who is behind the campaign.
The immediate risk is concentrated in organizations with Internet-exposed PaperCut Application Servers. PaperCut’s urgent security advisory tells administrators to restrict access to the products' web interfaces using firewall rules or network access controls, allowing connections only from trusted IP addresses.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.”
“We are aware of confirmed customer incidents and are treating this matter with the highest priority.”
PaperCut published the advisory on August 27, 2026, and says it has released emergency patches for customers with public-facing NG or MF Application Servers who cannot take other mitigating action. The advisory does not establish that the emergency fixes are a complete replacement for normal remediation across all deployments, so organizations should apply the fixes appropriate to their installation while keeping external access restricted.
What administrators should check
PaperCut has provided indicators that may help defenders identify a compromise. Administrators should review activity involving the legitimate pc-app.exe process and check whether server.log files have been modified, deleted, or are missing. The company also says to look for these errors in server.log:
ERROR No suitable driver found for jdbc:no:x

Recommended reading
ToxicPanda 2.0 turns Android banking malware into an enterprise threat
Sophia Reynolds • • 5 min read
ERROR DatabaseUtils — Database error looking up cardID: VALUES CAST
Those indicators are useful for triage, but they are not a clean test for exposure. PaperCut explicitly warns that a server without any of the listed signs may still have been compromised. The current advisory does not describe what attackers do after gaining access, whether they can move from a print server into the wider network, or whether customer data is being stolen.
The absence of an announced attacker objective leaves the operational impact unresolved. PaperCut has not said whether the campaign is focused on ransomware deployment, credential theft, network access, document archives, or another goal. It is continuing to investigate and says it will add indicators of compromise and remediation guidance as more information becomes available.
PaperCut has been a repeat target
This is not the first time Internet-facing PaperCut servers have drawn active exploitation. In April 2023, attackers exploited CVE-2023-27350, a critical vulnerability that allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable servers. Microsoft linked some of those intrusions to the Clop ransomware operation and also observed attacks that led to LockBit ransomware deployments.
The 2023 activity spread beyond a single criminal group. Iranian state-backed hacking groups were also observed exploiting CVE-2023-27350, while a joint CISA and FBI advisory in May 2023 said the Bl00dy ransomware gang was targeting the education sector. Clop said its use of the earlier vulnerabilities was aimed at gaining initial access to victim networks rather than directly stealing documents archived on PaperCut servers.
The earlier campaign is relevant to the current response, but it does not establish that the same actors or objectives are involved in the 2026 exploitation. PaperCut has not attributed the new attacks, and it has not published a CVE or a technical description of the vulnerability.
For now, the response is narrow: remove public access to the Application Server web interface, apply PaperCut’s emergency patch where applicable, and investigate the listed process and log indicators. A clean log review is not enough to clear a server while PaperCut’s investigation remains incomplete.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.


