{"id":2580,"date":"2026-08-28T08:54:53","date_gmt":"2026-08-28T08:54:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2580"},"modified":"2026-08-28T08:54:53","modified_gmt":"2026-08-28T08:54:53","slug":"papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2580","title":{"rendered":"PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 28, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg3avAnoYOOKqF8JpZv9Lng1lKE0AqmHOqM-Mq2T297NQrtDBM90yMYIzzVMHgzqytcCvFz7LuBXoPp-d9mRh0_dywBaM8NxZaiKPG0gDuYbSt2oRJdxSkHG5tWjxAMKvWUYZe6YINf_-7i5zUS7xGrDcaXulRvT5jVihWDJzAHSlaXQ6UYlHa6cPMpxbDC\/s1700-e365\/papercut.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>PaperCut has <a href=\"https:\/\/www.papercut.com\/kb\/Main\/security-bulletin-27-aug-2026-urgent-security-advisory\/\" target=\"_blank\">alerted<\/a> customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.<\/p>\n<p>The company has released an emergency patch for v25 and v26 to address the issue. It said it&#8217;s \u00abaware of confirmed customer incidents and is treating this matter with the highest priority.\u00bb An investigation into the incident is ongoing.<\/p>\n<p>The following indicators of compromise have been shared so far &#8211;<\/p>\n<ul>\n<li>Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from \u00abpc-app.exe\u00bb<\/li>\n<li>Missing, unexpectedly truncated, or deleted PaperCut server.log files<\/li>\n<li>\n    The presence of the below entries in \u00abserver.log\u00bb &#8211;<\/p>\n<ul>\n<li>ERROR No suitable driver found for jdbc:no:x<\/li>\n<li>ERROR DatabaseUtils &#8211; Database error looking up cardID: VALUES CAST<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>There are currently no details about the flaw, how it is being exploited, or who is behind the efforts. Users who have PaperCut NG\/MF Application Server exposed to the internet are advised to immediately restrict access to trusted IP addresses.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abUse firewall rules, network access controls, or equivalent measures to ensure the PaperCut server\u2019s web interfaces cannot be reached from untrusted internet addresses,\u00bb PaperCut said. \u00abTake this action now, even if you have not observed suspicious activity.\u00bb<\/p>\n<p>In 2023, a critical flaw in PaperCut MF and NG (CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.<\/p>\n<p><em>(This is a developing story. Please check back for more details.)<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 28, 2026Vulnerability \/ Enterprise Security PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2581,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[657,24,128,3209,867,126],"class_list":["post-2580","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-affecting","tag-attacks","tag-exploited","tag-papercut","tag-versions","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2580"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2580\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2581"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}