PaperCut warns active zero-day attacks are hitting PaperCut NG and MF print servers

PaperCut says attackers are actively exploiting an unknown vulnerability in its PaperCut NG and PaperCut MF print management software, and some customers have already been compromised. The company says all versions are affected, especially Internet-exposed Application Servers, but it has not yet published a CVE or technical details; PaperCut released emergency patches and advised restricting web interface access to trusted IP addresses and checking logs and pc-app.exe activity for signs of compromise.
Why it matters: Organizations running PaperCut NG or MF should treat this as urgent, especially if the server is reachable from the internet. Apply the emergency patch or lock down access immediately and investigate for compromise using PaperCut’s indicators while the vendor’s investigation continues.

Sources

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
info@thehackernews.com (The Hacker News) 2026.08.28 96% relevant
This appears to add the technical detail that attackers are chaining two PaperCut flaws to achieve unauthenticated code execution, updating the same active-attack event affecting PaperCut NG and MF servers.
PaperCut warns of hackers using printer management software flaw in attacks
2026.08.28 96% relevant
This source updates the same PaperCut NG/MF active-exploitation event with added specifics: the flaws are tracked as CVE-2026-82078 and CVE-2026-81578, PaperCut confirmed customer incidents, Huntress saw at least two impacted customers, and an initial patch was incomplete before a revised fix was released with help from Huntress and watchTowr.
PaperCut Releases Emergency Patch for Exploited Zero-Day
Eduard Kovacs 2026.08.28 97% relevant
This source directly updates the same event by reporting that PaperCut has now released emergency patches, reiterated mitigations such as removing internet exposure and restricting access to trusted IPs, and shared indicators of compromise including the suspicious file pc-app.exe and signs of tampered server.log files.
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
info@thehackernews.com (The Hacker News) 2026.08.28 98% relevant
This article appears to cover the same underlying event: PaperCut's warning that an actively exploited zero-day affects all supported and unsupported versions of PaperCut NG and MF print servers, reinforcing the breadth of exposure and urgency to isolate or patch when guidance becomes available.
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
2026.08.28 98% relevant
This article is a report on the same event and adds that a university security team alerted PaperCut to the attacks, notes the advisory is still withholding technical flaw details, and highlights the choice between an unofficial emergency patch and removing the web interface from the public internet.
PaperCut warns of NG, MF flaw exploited in zero-day attacks
Lawrence Abrams 2026.08.27 100% relevant
This article establishes a new tracked story because it reports a newly disclosed, actively exploited zero-day affecting all versions of PaperCut NG and MF, with emergency patches and mitigation guidance but no matching existing SecLog story for this 2026 event.
← Back to all stories