Skip to content
Active Exploitation of PaperCut Zero-Day Vulnerability

Active Exploitation of PaperCut Zero-Day Vulnerability

First seen 15 Sep 2026, 17:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 19:55 UTC
  • CVE-2026-1001 allows unauthenticated remote code execution in PaperCut NG and MF.
  • Active exploitation was confirmed shortly after the vulnerability's disclosure on August 27, 2026.
  • Patching efforts failed to secure systems, with the first two patches being bypassed.

In late August 2026, a zero-day vulnerability (CVE-2026-1001) in PaperCut NG and MF was exploited in the wild, with attackers actively targeting servers. The vulnerability, which allows unauthenticated remote code execution, was disclosed on August 27, 2026, but no patch was available at that time. The first emergency patch was released on August 28, but it was bypassed the same day. A third patch was issued on September 1, 2026, but the situation highlighted a critical gap in vulnerability response times, with disclosure-to-exploitation times now averaging mere hours. PaperCut's customers faced significant risks, as they had to assess their exposure without effective patches or public exploit code. This incident underscores the urgent need for improved vulnerability management in the cybersecurity landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-25
CVE-2026-1001 published
PaperCut disclosed a critical vulnerability allowing unauthenticated remote code execution.
Bleepingcomputer
2026-08-27
Vulnerability exploited in the wild
PaperCut issued an urgent advisory indicating that attackers were exploiting the vulnerability on servers.
Bleepingcomputer
2026-08-28
First emergency patch released
PaperCut released an emergency patch, which was bypassed on the same day.
Bleepingcomputer
2026-09-01
Third patch issued
A third patch was released to address the ongoing exploitation of the vulnerability.
Bleepingcomputer

More articles in this cluster (2)

Following this threat?

Track CVE-2026-1001 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed