Full Report
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
Analysis Summary
# Vulnerability: PaperCut NG/MF Zero-Day Exploitation
## CVE Details
*Note: As of the initial advisory date, a specific CVE identifier was not publicly assigned in the source text; however, it is being tracked as a critical zero-day.*
- **CVE ID:** Pending (Zero-Day)
- **CVSS Score:** Not yet rated (Estimated Critical based on vendor urgency)
- **CWE:** Unknown (Currently under investigation)
## Affected Systems
- **Products:** PaperCut NG, PaperCut MF
- **Versions:** All versions prior to the August 2026 emergency patches.
- **Configurations:** Systems with Application Servers exposed to the internet are at highest risk.
## Vulnerability Description
While technical specifics (such as the specific memory or logic flaw) have not been disclosed to prevent further exploitation, the vulnerability allows for unauthorized access or compromise of the PaperCut Application Server. The flaw was reproduced by PaperCut’s security team following reports from a University customer.
## Exploitation
- **Status:** Exploited in the wild (Zero-day attacks confirmed).
- **Complexity:** Undisclosed (Likely Low to Medium given the scale of active attacks).
- **Attack Vector:** Network (Internet-exposed web interfaces).
## Impact
- **Confidentiality:** High (Potential access to print logs, user data, and system credentials).
- **Integrity:** High (Confirmed reports of modified or deleted server log files).
- **Availability:** High (Potential for full server takeover or service disruption).
## Remediation
### Patches
- **Emergency Patches:** PaperCut has released emergency updates specifically for customers with public-facing servers. Administrators should log into their PaperCut customer portal to download the latest builds released on/after August 27, 2026.
### Workarounds
- **Network Restriction:** Immediately restrict access to the PaperCut web management interface (ports 9191/9192) to trusted IP addresses only using firewalls or Network Access Control (NAC).
- **Isolation:** If patching is not immediately possible, disconnect the Application Server from the public internet.
## Detection
### Indicators of Compromise (IoCs)
- **Process Monitoring:** Suspicious or anomalous activity originating from the `pc-app.exe` process.
- **Log Tampering:** Missing, deleted, or unexpectedly modified `server.log` files.
- **Log Errors:** Look for the following specific strings in `server.log`:
- `ERROR No suitable driver found for jdbc:no:x`
- `ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST`
*Warning: PaperCut notes that the absence of these indicators does not guarantee a server is uncompromised.*
## References
- **Vendor Advisory:** hxxps[://]www[.]papercut[.]com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
- **Source Report:** hxxps[://]www[.]bleepingcomputer[.]com/news/security/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/