Critical Zero-Day Exploitation of PaperCut NG/MF Vulnerability

Critical Zero-Day Exploitation of PaperCut NG/MF Vulnerability

First seen 27 Aug 2026, 17:17 UTC Feeds2.FeedburnerBleepingcomputerwww.papercut.com 76.5

Article Content

Browse articles
ThreatCluster

PaperCut Software has issued an urgent advisory regarding a zero-day vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. The company confirmed active exploitation in the wild, with confirmed attacks on customers. Organizations with publicly accessible PaperCut servers are advised to restrict access to trusted IP addresses immediately. The vulnerability allows attackers to exploit the software without prior authentication, posing a significant risk to affected systems. PaperCut's security team has reproduced the vulnerability using information from a university's security team. An emergency patch has been released for versions 25 and 26, and further indicators of compromise are expected as the investigation continues. The company has not disclosed details about the attackers or the nature of the exploitation. Administrators should monitor for specific errors in server logs and suspicious activity from the pc-app.exe process.

Key Points: • Active zero-day vulnerability in PaperCut NG/MF software confirmed. • Emergency patch released for versions 25 and 26; immediate action required. • Organizations must restrict access to servers exposed to the internet.

Timeline

2023-04-20
CVE-2023-27350 published
Critical vulnerability disclosed allowing unauthenticated remote code execution on PaperCut servers.
Bleepingcomputer
2023-04-21
CVE-2023-27350 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Bleepingcomputer
2026-08-27
PaperCut issues urgent security advisory
PaperCut warns of ongoing exploitation of a vulnerability affecting NG and MF versions, urging immediate action.
Bleepingcomputer
2026-08-27
Emergency patch released
PaperCut releases an emergency patch for versions 25 and 26 to mitigate the vulnerability.
www.papercut.com