logo

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

ID: 047c3d2f-7a21-5a3c-96dc-ee11c1839b3f

STIX ID: report--047c3d2f-7a21-5a3c-96dc-ee11c1839b3f

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: [email protected] (The Hacker News)

...
...

PaperCut warned of active zero-day exploitation against all versions of PaperCut NG/MF, released emergency patches for v25 and v26, and confirmed customer incidents. The advisory lists IOCs—suspicious post-exploitation activity from pc-app.exe, missing or truncated server.log files, and specific error log entries—and urges immediate restriction of internet access to PaperCut servers while investigations continue; the report also notes that a prior critical PaperCut flaw (CVE-2023-27350) was previously abused by ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.