// news

PaperCut NG/MF Zero-Day Under Active Attack: What Defenders Should Do Now

On 27 August 2026, PaperCut — one of the most widely deployed print-management products in enterprises and universities — confirmed active exploitation of a zero-day vulnerability in PaperCut NG and PaperCut MF. In the early hours of 28 August (2:10 a.m. AEST) the vendor shipped emergency, out-of-cycle builds for the v25 and v26 branches across Windows, Linux, and macOS. No CVE has been assigned yet and technical details are being withheld, but exploitation in the wild is already confirmed in customer incidents.

The detail that turns this from routine patch news into an emergency: every supported version is affected. Your build number is irrelevant to exposure. If a PaperCut Application Server faces the internet, you are in scope right now.

Why a print server is a prime target

A print server looks like boring plumbing, which is exactly why it gets under-defended. In practice it’s one of the most convenient footholds in a network:

  • High privilege. The PaperCut service typically runs as SYSTEM on Windows or root on Linux. Remote code execution there means immediate code execution at the highest privilege on the host — no separate privilege-escalation step required.
  • Domain reach. It integrates with Active Directory / LDAP, stores and validates credentials, and usually holds a service account with broad rights — a great launchpad for lateral movement toward a domain controller.
  • Central position. Nearly every workstation talks to it, making it ideal for persistence and internal reconnaissance.
  • It gets exposed. The admin web interface and ports 9191/9192/9193 are routinely reachable from the internet “for easier administration.”

We’ve seen this before — and it’s repeating

PaperCut burned badly in April 2023: CVE-2023-27350 delivered unauthenticated RCE and was weaponized almost instantly. Per CISA and the FBI, it was exploited by Cl0p and LockBit operators, the Bl00dy gang (hitting the education sector at scale), and Iranian state-backed actors. The chain back then was simple: bypass the admin authentication, then run arbitrary code through the print-script settings. The 2023 lesson still stands — a product with a rich auth-bypass history has become an entry door again. The only difference now is that the gap between disclosure and exploitation has collapsed from weeks to hours.

Indicators of compromise

The vendor and researchers point to a few artifacts to check first:

  • Suspicious behavior from the legitimate pc-app.exe process — for example, spawning shell child processes.
  • server.log files that are modified, truncated, deleted, or missing (log tampering to cover tracks).
  • Anomalous log errors such as ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.

Important caveat: a lack of indicators does not mean the server is clean. A capable attacker cleans up, and the vulnerability details are still private — so if the server was internet-facing, operate on an assume-breach basis.

What to do right now — a checklist

  1. Patch immediately. Apply the emergency v25/v26 builds for your OS. This is an out-of-cycle release aimed at this attack, not a routine update — don’t wait for a maintenance window.
  2. Take the web interface off the internet. If you can’t patch this second, restrict the admin interface and ports 9191-9193 to trusted IPs via firewall rules, or put it behind a VPN. A print server almost never needs to be publicly reachable.
  3. Check your exposure. Use Shodan/Censys (the PaperCut banner, characteristic ports) to confirm your server isn’t hanging out in the open. Attackers are running the same query — it’s a race.
  4. Collect IOCs. Inspect server.log for gaps and edits, review pc-app.exe behavior, and grep for the database errors above. Correlate with EDR telemetry.
  5. Segment. A print server should not have broad access to the domain and file shares. Constrain its network reach by least privilege — that breaks lateral movement even if RCE already happened.
  6. If you find traces, go to incident mode. Isolate the host, rotate the service and domain credentials it could reach, and capture a forensic image before rebuilding. A rebuild “over the top” without root-cause analysis leaves the backdoor in place.

The takeaway

PaperCut is a specific instance of a systemic problem: far more is exposed than organizations think, and n-day or zero-day bugs in “boring” infrastructure (print, VPN gateways, file balancers) turn into SYSTEM-level RCE faster than an official CVE even lands. Patch management is necessary but not sufficient — it reacts, it doesn’t anticipate. What works is continuous external-attack-surface inventory and external network penetration testing that finds exposed services like PaperCut, stale versions, and paths to the domain before an attacker does.

If you’re not certain what of yours faces the internet — or how far an attacker could pivot from a print server — that’s precisely our work. External network penetration testing maps the exposed surface; internal network testing and Active Directory penetration testing show the real path from a foothold to domain compromise; and an assumed-breach assessment answers “if they’re already in, how bad is it?” Get in touch and we’ll scope your perimeter and tell you what to close first.

Sources: PaperCut security bulletins (3 and 27 August 2026); reporting by BleepingComputer, Help Net Security, CybersecurityNews; historical context from CISA/FBI advisories on CVE-2023-27350.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement