T

Threats

PaperCut NG/MF Vulnerability Under Active Exploitation

PaperCut has confirmed customer incidents involving active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. The vendor reproduced the vulnerability using information supplied by a university customer and its incident response team.

The vulnerability's technical cause, CVE identifier, severity and CVSS score have not been published as of 28 August 2026. Do not wait for further technical disclosure before taking action.


Overview

  • Vendor: PaperCut Software

  • Products: PaperCut NG and PaperCut MF

  • CVE: Not assigned or disclosed as of 28 August 2026

  • Severity: Not yet published by PaperCut

  • CVSS: Not yet published by PaperCut

  • Exploitation: Confirmed active exploitation affecting customers

  • Published: 27 August 2026 AEST

  • Updated: 28 August 2026 AEST


Affected Versions

PaperCut NG

  • Affected: All versions of PaperCut NG

  • Fixed: Emergency patch packages are available for v25 and v26. PaperCut has not published an exact patched build number as of 28 August 2026. A v24 build remains in progress.

  • Not affected: PaperCut has not identified an unaffected PaperCut NG version.

  • Source: PaperCut NG/MF Security Bulletin, 27 August 2026

PaperCut MF

  • Affected: All versions of PaperCut MF

  • Fixed: Emergency patch packages are available for v25 and v26. PaperCut has not published an exact patched build number as of 28 August 2026. A v24 build remains in progress.

  • Not affected: PaperCut has not identified an unaffected PaperCut MF version.

  • Source: PaperCut NG/MF Security Bulletin, 27 August 2026


Vulnerability Breakdown

CVE Not Yet Assigned - Actively Exploited PaperCut NG/MF Vulnerability

  • Severity: Not published

  • CVSS: Not published

  • Description: PaperCut is investigating an undisclosed vulnerability affecting every version of PaperCut NG and PaperCut MF. The vendor has confirmed customer incidents and reproduced the issue, but has not disclosed the vulnerability class or exploitation method.

  • Impact: PaperCut has not yet published the verified impact or post-exploitation actions.

  • Conditions: Internet-accessible PaperCut Application Servers are the immediate focus of PaperCut's mitigation guidance.

  • Exploitation status: Actively exploited.


Indicators of Compromise

Review the PaperCut Application Server for:

  • Alerts from intrusion detection, endpoint security or network monitoring tools, particularly suspicious post-exploitation activity involving pc-app.exe.

  • Missing, unexpectedly truncated or deleted server.log files.

  • ERROR No suitable driver found for jdbc:no:x in server.log.

  • ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST in server.log.

The absence of these indicators does not confirm that a system is unaffected.


Mitigation

  • Immediately restrict PaperCut NG/MF web interfaces to trusted IP addresses using firewall rules, network access controls or equivalent controls.

  • Remove public internet access to the Application Server wherever possible.

  • For public-facing servers where other mitigation is not possible, apply PaperCut's emergency patch for v25 or v26 using the packages in the vendor bulletin.

  • Continue monitoring the vendor bulletin for the v24 patch, validated indicators of compromise and further remediation guidance.

  • If Card/ID number lookups use an external database, review the vendor FAQ before patching. Patched builds block SQL queries containing EXEC, EXECUTE or CALL for this feature.

  • Investigate any identified indicators through the organisation's incident response process.


Summary for IT Teams

  • Products: PaperCut NG and PaperCut MF

  • Threat Level: Urgent, confirmed active exploitation. Vendor severity and CVSS are pending.

  • Action Required: Restrict Application Server access to trusted IP addresses immediately. Apply the emergency patch for v25 or v26 where necessary, review available indicators and monitor PaperCut's bulletin for updates.


Reference


Need Help?

Secure ISS can help assess PaperCut exposure, restrict access, review indicators and support emergency patching. Contact us on 1300 769 460 or email the Secure ISS team.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.