PaperCut NG and MF actively exploited zero-day security flaw
Vulnerability
Summary
Hide ▲
Show ▼
PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk. PaperCut said it has confirmed customer incidents, released emergency patches for v25 and v26, and shared indicators of compromise tied to pc-app.exe and server.log tampering or deletion. The company advised administrators to restrict the PaperCut Application Server to trusted IP addresses using firewall rules or network access controls. No public flaw details or actor attribution have been released.
Related Happenings
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
Vulnerability
H score53
First: 28.08.2026 20:12
Last: 28.08.2026 20:12
Sources 1
About this happening:
PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...
PaperCut NG and MF auth-bypass RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: PaperCut NG/MF vulnerability activity now includes active exploitation of CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code executi...
Latest development: 10.09.2026 14:41
A suspected Russian-speaking actor used OpenAI Codex and a DeepSeek model to research, validate, and deploy exploits for CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF, then used the workflow to compromise at least 440 instances across 395 victim organizations in 48 countries, with education-sector victims in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentHow related: PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
H score22
First: 12.08.2026 16:35
Last: 12.08.2026 16:35
Sources 1
About this happening:
Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
CampaignAbout this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Latest development: 12.08.2026 18:38
Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
Incident
H score26
First: 06.08.2026 21:22
Last: 06.08.2026 21:22
Sources 1
About this happening:
Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
IncidentAbout this happening: Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score79
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Timeline
-
27.08.2026 19:31 3 articles · 13d ago
PaperCut warns of active zero-day exploitation in NG and MF
Initial DisclosurePaperCut says hackers are actively exploiting a vulnerability affecting all versions of PaperCut NG and PaperCut MF, and it is aware of confirmed customer incidents. The company urges organizations with Internet-exposed PaperCut Application Servers to restrict web access to trusted IP addresses, has released emergency patches for public-facing PaperCut NG/MF servers, and shared indicators of compromise including suspicious activity from the legitimate pc-app.exe process and server.log files that have been modified, deleted, or are missing.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — thehackernews.com — 28.08.2026 11:25