PaperCut emergency patches for public-facing NG/MF servers
Security Patch Release
Summary
Hide ▲
Show ▼
PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the print management software. The company released an emergency patch for v25 and v26 and said it has confirmed customer incidents involving Internet-exposed PaperCut Application Servers. PaperCut also shared indicators of compromise, including suspicious activity from pc-app.exe and altered or missing server.log files, and told customers to restrict exposure with firewall rules or network access controls.
Related Happenings
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation Wave
H score56
First: 01.09.2026 20:53
Last: 01.09.2026 20:53
Sources 1
About this happening:
Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
JFrog Artifactory CVE-2026-82329 exploitation wave
Exploitation WaveAbout this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentHow related: PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
H score22
First: 12.08.2026 16:35
Last: 12.08.2026 16:35
Sources 1
About this happening:
Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
CampaignAbout this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Latest development: 12.08.2026 18:38
Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation Wave
H score48
First: 12.08.2026 12:01
Last: 12.08.2026 12:01
Sources 1
About this happening:
Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code executio...
Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)
Exploitation WaveAbout this happening: Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code executio...
Timeline
-
01.09.2026 10:48 1 articles · 9d ago
PaperCut NG/MF zero-days abused for data theft
Exploitation ObservedAttackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.
Show sources
- Recently patched PaperCut zero-days used in data theft attacks — www.bleepingcomputer.com — 01.09.2026 10:48
-
27.08.2026 19:31 1 articles · 13d ago
PaperCut warns of active zero-day exploitation in PaperCut NG and PaperCut MF
Initial DisclosurePaperCut says it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF, warns that hackers are using zero-day attacks against all versions, and says it is aware of confirmed customer incidents involving Internet-exposed PaperCut Application Servers.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
-
27.08.2026 19:31 5 articles · 13d ago
PaperCut releases emergency patches for public-facing PaperCut NG/MF servers
Mitigation Patch UpdatePaperCut releases emergency patches for customers with public-facing PaperCut NG/MF servers and tells administrators who cannot patch immediately to use firewall rules or network access controls to restrict web interfaces to trusted IP addresses.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — thehackernews.com — 28.08.2026 11:25
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — thehackernews.com — 28.08.2026 20:12
- PaperCut releases second emergency patch for exploited flaws — www.bleepingcomputer.com — 28.08.2026 22:08
-
27.08.2026 19:31 1 articles · 13d ago
PaperCut shares indicators of compromise for suspected server compromise
Detection Ioc UpdatePaperCut shares indicators of compromise for potentially compromised servers, including suspicious activity from the legitimate PaperCut pc-app.exe process, server.log files that have been modified, deleted, or are missing, and server.log errors such as 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST', while warning that a lack of indicators does not prove a server is clean.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31