logo

PaperCut Remote Code Execution Vulnerability Exploited in the Wild

ID: 7ce927db-db3a-544d-8bcf-4c5a7add2876

STIX ID: report--7ce927db-db3a-544d-8bcf-4c5a7add2876

Feed Name: FortiGuard Threat Signals

Threat Score
85/100

Date Published: 2025-07-24

Date Updated: 2026-07-28

...
...

**FortiGuard Labs Alert:** CVE-2023-27350 is a critical (CVSS 9.8) authentication-bypass RCE in PaperCut MF/NG (versions 8.0+), actively exploited in the wild to deploy remote management/maintenance tools and Truebot malware (linked to Clop); vendor patches are available and FortiGuard has released AV signatures, an IPS signature, and webfiltering to block reported post-exploitation IOCs—apply vendor patches and mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.