PaperCut warned of active exploitation of an undisclosed security vulnerability in all versions of the PaperCut NG and PaperCut MF print management software, confirming that it had received reports of incidents affecting customers. The company urged organizations operating internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces before attackers can exploit them.
PaperCut published an urgent security notice on August 27, 2026, explaining that its security response team was investigating active exploitation and that the company had reproduced the vulnerability based on information provided by a university. The company has not yet disclosed details about the vulnerability or its exploitation method, nor has it identified the parties behind the attacks or what the attackers do after compromising the servers.
Immediate Action for Exposed Servers
PaperCut released an emergency patch for customers with publicly accessible NG or MF servers who cannot take other mitigation measures. Along with installing the patch, the company recommends using firewall rules or network access controls to limit the web interfaces to trusted IP addresses only.
These recommendations apply to servers accessible from the internet, which is the point the company emphasized in its urgent warning. The details of the fixed versions or the nature of the software change were not mentioned in the available material, so it is not possible to determine the extent to which additional steps are required after applying the patch.
Indicators That May Point to a Compromise
PaperCut shared indicators of compromise that administrators can use for an initial examination, but it cautioned that the absence of these indicators does not prove that a server is safe. The indicators include:
- Suspicious activity associated with the legitimate process pc-app.exe.
- Modification, deletion, or loss of server.log files.
- The appearance of the error ERROR No suitable driver found for jdbc:no:x.
- The appearance of the error ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
Why Does This Warning Matter?
The significance of the development stems from the combination of three factors: the vulnerability is being actively exploited, it affects all NG and MF versions according to PaperCut, and the company confirmed incidents involving customers before publishing complete technical details. This makes restricting access to the interface and examining logs urgent practical measures, rather than merely proactive recommendations.
PaperCut has previously attracted exploitation campaigns after vulnerabilities in its products were disclosed. In April 2023, the critical vulnerability CVE-2023-27350 was exploited to bypass authentication and execute code remotely on vulnerable servers. Microsoft linked some of those attacks to the Clop ransomware operation, while it also observed operations that led to LockBit attacks and reported that Iran-backed groups had exploited the vulnerability as well. In May 2023, CISA and the FBI warned that the Bl00dy Ransomware gang was exploiting it against the education sector.
These precedents do not prove that the same parties are behind the current campaign, but they explain why PaperCut is treating it as a high-priority incident. The company says it will update its notice with indicators of compromise and additional remediation guidance as the investigation progresses, while the nature of the data the attackers may have accessed remains unknown.