PaperCut Software has disclosed a critical zero-day vulnerability affecting all versions of its NG and MF print management products, with the company confirming that attackers are actively exploiting the flaw in real-world incidents targeting customers across multiple sectors.
The company published an urgent security advisory on August 27, warning that the vulnerability allows unauthenticated remote code execution. This means attackers can take complete control of PaperCut servers without needing any valid login credentials, a severity level that has prompted emergency action from the vendor.
“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only,” the advisory stated. “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity.”
Emergency Patches Released Without Full Validation
PaperCut released emergency patches on Friday for customers with public-facing NG/MF servers. However, the company cautioned that the patches have not completed its normal quality assurance validation process, making them an interim fix rather than a fully tested release. Organizations unable to apply the patch are advised to take their PaperCut servers offline entirely until an official, validated update becomes available.
The vulnerability has been assigned CVE identifiers CVE-2026-81578 and CVE-2026-82078, forming a pre-authentication remote code execution chain. PaperCut has not yet shared technical details about the specific flaw being exploited or post-compromise behaviors observed by its security team. The company said its investigation is ongoing and it would update the advisory with additional findings.
PaperCut shared initial indicators of compromise, including suspicious activity from the legitimate PaperCut pc-app.exe process and server.log files that have been modified, deleted, or are missing. The company warned that the absence of these indicators does not confirm a system has not been compromised, urging a presumption of risk for any unpatched server.
A Platform With a Troubling Track Record
PaperCut print management software is deployed across thousands of organizations worldwide, including schools, universities, healthcare providers, government agencies, and large enterprises. The platform handles print job routing, user authentication, and device management, giving administrators broad visibility into organizational printing infrastructure and cost allocation.
The company has been repeatedly targeted after security vulnerabilities. In April 2023, attackers exploited critical flaw CVE-2023-27350 to bypass authentication and execute code remotely on PaperCut servers. Microsoft linked some of those attacks to the Clop ransomware operation, which used compromised PaperCut servers as an initial access vector into victim networks.
Iranian state-backed hacking groups also exploited the same 2023 vulnerability, and the FBI issued a joint advisory warning that the Bl00dy Ransomware Gang was targeting education organizations through vulnerable PaperCut servers. The pattern of repeated exploitation has established PaperCut as a favored target for both financially motivated criminals and nation-state actors.
Scale of the Risk Across Critical Sectors
The breadth of PaperCut deployment means the current zero-day affects a vast and distributed attack surface. Educational institutions represent a particularly large portion of the customer base, as the software integrates with student information systems and provides cost-tracking features valued by university administrators across the globe.
Healthcare organizations also rely on PaperCut to manage secure printing of patient records and comply with data protection regulations. A compromise of these systems could expose sensitive printing logs or serve as a lateral movement point into broader hospital networks, compounding the damage well beyond the print management layer itself.
Security researchers noted that the zero-day unauthenticated nature makes it especially dangerous in the current threat landscape. Attackers do not need to steal or guess any credentials to achieve code execution, and the vulnerability affects every version of both PaperCut NG and PaperCut MF, leaving no safe version for organizations that have not yet applied the emergency fix.
Organizations running PaperCut are urged to immediately restrict internet access to their application servers, apply the emergency patch if direct network restriction is not feasible, and monitor for the published indicators of compromise while awaiting a fully validated security update from the vendor.
discussion