PaperCut Warns of NG, MF Flaw Exploited in Zero-Day Attacks
PaperCut said it has confirmed customer incidents and urged users with public-facing servers to apply an emergency patch or take systems offline.
- PaperCut Software issued an urgent security advisory Thursday confirming active exploitation of a zero-day vulnerability affecting its NG and MF print management products, stating it is "aware of confirmed customer incidents and treating this matter with the highest priority."
- The vulnerability targets public-facing Application Servers; Thankfully, administrators can mitigate risk by moving web interfaces off the public internet and restricting access to trusted internal addresses.
- An emergency patch is available for customers unable to take other action, though PaperCut warns the patch is not an official release; the FAQ notes it "have not gone through our usual release process."
- The Register reports many users may prefer taking servers offline ASAP, as applying unvalidated emergency software presents challenges and finding a change window to install patches remains difficult.
- Fashioning a permanent solution is ongoing, and Communicating the nature of the flaw is difficult to avoid inviting further attacks; PaperCut will advise users once a better fix lands.
18 Articles
18 Articles
PaperCut Zero-Day Exploit: NG, MF Vulnerability Warning
Active Exploitation Warning: PaperCut has confirmed a zero-day vulnerability in NG and MF software allowing unauthenticated remote Java code execution. Emergency Remediation: Priority patches are available for versions 25 and 26, while administrators are advised to restrict public internet access to Application Server interfaces. Active Zero-Day Attacks Target Print Management PaperCut issued an urgent security advisory on August 27, 2026, warni…
Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful. Such attacks are the risk to which users of PaperCut print management software find themselves exposed today, after the company revealed a university’s security teams alerted it to an attack. The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut…
Multiple vulnerabilities have been discovered in Papercut. They allow an attacker to bypass authentication and execute arbitrary code remotely. Papercut indicates that these vulnerabilities are actively exploited. The editor explains that the patch blocks requests... See online: https://www.cert.ssi.gouv.fr/avis/C...
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










