Illustrative image generated with AI
Zero-day in PaperCut NG and MF: Actively Exploited, All Versions at Risk
PaperCut NG/MF zero-day flaw actively exploited; all versions at risk. No CVE assigned. Emergency patches released; check for IOCs and restrict web access.
Text generated by artificial intelligence, published without human review. AI transparency
A New Vulnerability with No CVE and Confirmed Compromises
On August 27, 2026, it emerged that PaperCut Software issued an urgent advisory about a vulnerability being exploited as a zero-day against PaperCut customers. The flaw affects all versions of PaperCut NG and PaperCut MF and concerns the PaperCut Application Server, particularly installations with the web interface exposed to the Internet. No CVE has been assigned yet, and no technical details about the flaw or exploit vector have been disclosed.
PaperCut confirms customer incidents and treats the issue as a priority. The security team has reproduced the vulnerability using information provided by a university customer. No threat actors, post-compromise actions, or possible data exfiltration have been revealed. It is not known when the compromises began.
No CVSS score or CWE classification is available for the new flaw. Its operational significance comes from active exploitation and the fact that all versions are affected.
Immediate Countermeasures: Firewall and Emergency Patches
PaperCut has released emergency patches for customers with public PaperCut NG/MF servers that cannot implement other countermeasures. The first recommendation is to immediately restrict access to the web interface of exposed Application Servers to trusted IPs only, through firewall rules or network access controls. If restrictions cannot be applied, installing the emergency patches is recommended.
There are still no details on the exploit mechanism: PaperCut has not explained whether it is an authentication bypass, code execution, or something else. The absence of a CVE makes automated tracking more difficult for security teams, but the operational priority remains reducing exposure and updating.
Indicators of Compromise to Look For
PaperCut has reported some indicators for the current campaign:
- suspicious activity from the legitimate process
pc-app.exe; server.logfiles modified, deleted, or missing;- errors in
server.log:ERROR No suitable driver found for jdbc:no:xandERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
The absence of these indicators does not rule out compromise. PaperCut has stated that the advisory will be updated with additional IOCs and remediation guidance.
The Precedent: CVE-2023-27350, Critical 9.8 and Used in Ransomware
The new zero-day does not come to a product with no history. In April 2023, active exploitation began of CVE-2023-27350, a critical vulnerability with a CVSS score of 9.8 and vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw allowed remote attackers to bypass authentication on PaperCut NG 22.0.5 (Build 63914) installations and execute arbitrary code in the SYSTEM context. The defect resided in the SetupCompleted class and was caused by improper access control (CWE-284). The ZDI reference was ZDI-CAN-18987.
The versions affected by CVE-2023-27350 were PaperCut MF and PaperCut NG earlier than 20.1.7. On April 21, 2023, CISA added the vulnerability to the KEV catalog, with a remediation deadline for U.S. federal agencies of May 12, 2023. The required action was to apply updates according to the vendor's instructions.
CVE-2023-27350 has been used in ransomware campaigns. Microsoft linked some intrusions to the Clop operation, used for initial access, and observed attacks that led to LockBit ransomware. Clop stated that it used the flaw for initial access and not to steal documents archived directly from PaperCut servers, although the Print Archiving feature may store documents. Microsoft also reported state-sponsored Iranian hacking groups using the CVE. In May 2023, a joint CISA/FBI advisory described the Bl00dy ransomware gang exploiting vulnerable PaperCut servers against the education sector.
For the new zero-day, since no CVE has been assigned, there is currently no entry in CISA's KEV catalog.
What to Do Now
Anyone managing PaperCut NG or MF servers should assume that direct Internet exposure is the main risk. There are three immediate actions: restrict access to the web interface to trusted addresses only, apply emergency patches where restriction is not possible, and search logs for the reported indicators. The search should also extend to systems where server.log is missing or altered, because log deletion is itself a signal.
It is not yet clear whether the new flaw has impacts similar to CVE-2023-27350, i.e., code execution as SYSTEM and authentication bypass. The fact that all versions are affected and the confirmed compromises justify immediate action, without waiting for technical details or a CVE. PaperCut has indicated that it will update the advisory with additional IOCs and remediation guidance: those who have already applied the first mitigations should monitor for updates.
Sources
This article is an original reworking based on the sources below.
