T
Threats
PaperCut NG/MF Vulnerability Under Active Exploitation
PaperCut has confirmed customer incidents involving active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. The vendor reproduced the vulnerability using information supplied by a university customer and its incident response team.
The vulnerability's technical cause, CVE identifier, severity and CVSS score have not been published as of 28 August 2026. Do not wait for further technical disclosure before taking action.
Overview
Vendor: PaperCut Software
Products: PaperCut NG and PaperCut MF
CVE: Not assigned or disclosed as of 28 August 2026
Severity: Not yet published by PaperCut
CVSS: Not yet published by PaperCut
Exploitation: Confirmed active exploitation affecting customers
Published: 27 August 2026 AEST
Updated: 28 August 2026 AEST
Affected Versions
PaperCut NG
Affected: All versions of PaperCut NG
Fixed: Emergency patch packages are available for v25 and v26. PaperCut has not published an exact patched build number as of 28 August 2026. A v24 build remains in progress.
Not affected: PaperCut has not identified an unaffected PaperCut NG version.
PaperCut MF
Affected: All versions of PaperCut MF
Fixed: Emergency patch packages are available for v25 and v26. PaperCut has not published an exact patched build number as of 28 August 2026. A v24 build remains in progress.
Not affected: PaperCut has not identified an unaffected PaperCut MF version.
Vulnerability Breakdown
CVE Not Yet Assigned - Actively Exploited PaperCut NG/MF Vulnerability
Severity: Not published
CVSS: Not published
Description: PaperCut is investigating an undisclosed vulnerability affecting every version of PaperCut NG and PaperCut MF. The vendor has confirmed customer incidents and reproduced the issue, but has not disclosed the vulnerability class or exploitation method.
Impact: PaperCut has not yet published the verified impact or post-exploitation actions.
Conditions: Internet-accessible PaperCut Application Servers are the immediate focus of PaperCut's mitigation guidance.
Exploitation status: Actively exploited.
Indicators of Compromise
Review the PaperCut Application Server for:
Alerts from intrusion detection, endpoint security or network monitoring tools, particularly suspicious post-exploitation activity involving
pc-app.exe.Missing, unexpectedly truncated or deleted
server.logfiles.ERROR No suitable driver found for jdbc:no:xinserver.log.ERROR DatabaseUtils - Database error looking up cardID: VALUES CASTinserver.log.
The absence of these indicators does not confirm that a system is unaffected.
Mitigation
Immediately restrict PaperCut NG/MF web interfaces to trusted IP addresses using firewall rules, network access controls or equivalent controls.
Remove public internet access to the Application Server wherever possible.
For public-facing servers where other mitigation is not possible, apply PaperCut's emergency patch for v25 or v26 using the packages in the vendor bulletin.
Continue monitoring the vendor bulletin for the v24 patch, validated indicators of compromise and further remediation guidance.
If Card/ID number lookups use an external database, review the vendor FAQ before patching. Patched builds block SQL queries containing
EXEC,EXECUTEorCALLfor this feature.Investigate any identified indicators through the organisation's incident response process.
Summary for IT Teams
Products: PaperCut NG and PaperCut MF
Threat Level: Urgent, confirmed active exploitation. Vendor severity and CVSS are pending.
Action Required: Restrict Application Server access to trusted IP addresses immediately. Apply the emergency patch for v25 or v26 where necessary, review available indicators and monitor PaperCut's bulletin for updates.
Reference
Need Help?
Secure ISS can help assess PaperCut exposure, restrict access, review indicators and support emergency patching. Contact us on 1300 769 460 or email the Secure ISS team.

