PaperCut NG/MF Zero-Day Exploitation
First seen Aug 28, 2026 · Updated Aug 28, 2026
PaperCut has disclosed active zero-day exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. Attackers are leveraging the flaw in real-world attacks prior to patch availability or widespread patch adoption, echoing previous high-profile PaperCut exploitation campaigns.
Technical Analysis
PaperCut NG and MF are widely deployed print management platforms in enterprise and educational environments, historically targeted due to their SYSTEM-level web application service and network-exposed admin interfaces. The current advisory indicates active exploitation without full technical details on the vulnerability class (RCE, auth bypass, or SSRF are the most common categories in prior PaperCut CVEs such as CVE-2023-27350 and CVE-2023-27351). Exploitation of print management servers typically leads to remote code execution with SYSTEM privileges, enabling attackers to deploy further payloads, establish persistence, or pivot laterally across the network. Organizations should treat this as a high-priority patching event given PaperCut's track record of being weaponized by ransomware affiliates (e.g., Bl00dy, LockBit-linked actors) shortly after disclosure. If PaperCut servers reside on networks that also host AI agent orchestration tools, RAG pipelines, or automation infrastructure, compromise could expose stored credentials, API keys, or provide an initial foothold for lateral movement into agent-connected systems.
Affected Systems
All versions of PaperCut NG and PaperCut MF print management software (specific vulnerable version range pending official CVE and patch details from vendor advisory)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) published at this time; monitor PaperCut and CISA advisories for updates
Remediation Steps
- 1
Apply vendor patches immediately
Monitor PaperCut's official security advisory page and apply patched versions of PaperCut NG/MF as soon as they are released.
- 2
Restrict network exposure
Limit access to PaperCut admin interfaces (default ports 9191/9192) to trusted internal networks only; disable external/internet-facing access.
- 3
Monitor for exploitation indicators
Review PaperCut server logs for unusual process spawning (e.g., cmd.exe, powershell.exe from the PaperCut service account) and unexpected outbound connections.
- 4
Implement network segmentation
Isolate print management servers from critical infrastructure, credential stores, and any AI agent or automation frameworks to limit lateral movement potential.
- 5
Deploy EDR/monitoring
Ensure endpoint detection and response tooling is active on PaperCut application servers to catch post-exploitation activity.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.