🇮🇳
स्वतंत्रता दिवस की हार्दिक शुभकामनाएं! 🇮🇳 Happy Independence Day! | Har Ghar Tiranga | देश के 80वें स्वतंत्रता दिवस पर आज़ादी का अमृत महोत्सव मनाएं! - Celebrate the 80th Independence Day of India!

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut Issues Urgent Security Advisory as Zero-Day Exploit Targets Print Management Software

By Ravie Lakshmanan
August 28, 2026

Print management software provider PaperCut has issued an emergency security bulletin, warning customers that a critical vulnerability in its PaperCut NG and PaperCut MF platforms is currently being actively exploited in the wild.

The zero-day flaw impacts all versions of the software, prompting the company to release immediate patches for versions 25 and 26. In an urgent advisory, PaperCut confirmed it is investigating reports of active exploitation, characterizing the situation as a matter of the “highest priority.”

Indicators of Compromise (IoC)

While specific details regarding the technical nature of the vulnerability—such as the attack vector or the identity of the threat actors—remain undisclosed, PaperCut has provided several indicators of compromise to help administrators identify potential breaches:

  • Suspicious Process Activity: Alerts from endpoint security, intrusion detection, or network monitoring tools flagging unusual behavior originating from the “pc-app.exe” process on the PaperCut Application Server.
  • Log Tampering: Evidence of missing, unexpectedly truncated, or completely deleted server logs.
  • Error Logs: The presence of specific database-related error entries in the server.log file, including:
    • ERROR No suitable driver found for jdbc:no:x
    • ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Immediate Mitigation Measures

PaperCut is urging all users, particularly those with Application Servers exposed to the internet, to take defensive action immediately. Even if organizations have not yet detected signs of compromise, the company recommends restricting access to the server’s web interfaces.

“Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses,” the advisory stated. “Take this action now, even if you have not observed suspicious activity.”

A History of Exploitation

The current situation echoes a serious incident from April 2023, when a critical vulnerability in PaperCut software (CVE-2023-27350, carrying a maximum CVSS score of 9.8) became a primary target for malicious actors. During that campaign, both state-sponsored Russian hackers and the financially motivated cybercriminal group Lace Tempest utilized the flaw to facilitate the deployment of Cl0p and LockBit ransomware.

Security researchers are closely monitoring this zero-day event as the investigation continues. Organizations utilizing PaperCut are advised to monitor the company’s official knowledge base for further updates and to prioritize applying the emergency patches as soon as possible.

(This is a developing story. Please check back for more details.)

Leave a Reply

Your email address will not be published. Required fields are marked *