TechNewsReel
Live

PaperCut Issues Emergency Patches for Actively Exploited Zero-Day

All versions of PaperCut NG and MF print management software are at risk as attackers exploit a critical flaw in the wild.

TechNewsReel Newsroom · August 28, 2026

PaperCut has issued an emergency alert after discovering a zero-day vulnerability affecting its entire suite of print management software. The company confirmed that malicious actors are already exploiting the flaw in active attacks, placing a wide array of corporate and educational networks at immediate risk.

The vulnerability impacts all versions of both PaperCut NG and PaperCut MF. In response to the active exploitation, PaperCut has released emergency patches specifically for versions v25 and v26 to mitigate the security risk. The company stated it is "aware of confirmed customer incidents and is treating this matter with the highest priority."

Infrastructure at Risk

PaperCut NG and MF are industry-standard solutions used by organizations to manage printing costs and maintain document security. Because these tools sit at the intersection of network infrastructure and physical hardware, they are high-value targets for attackers. Zero-day exploits in this type of infrastructure software typically provide a gateway for unauthorized access or remote code execution, allowing attackers to pivot from a print server into deeper, more sensitive areas of a corporate network.

Industry Implications

The scale of this vulnerability is significant because it is not limited to a single build or a specific configuration; it spans all versions of the software. This creates a massive attack surface across thousands of environments globally. Until administrators apply the emergency patches, these organizations remain vulnerable to compromise, potentially leading to data breaches or the deployment of ransomware via the print management gateway.

Next Steps for Administrators

Organizations utilizing PaperCut NG or MF are urged to prioritize the deployment of the v25 and v26 patches immediately. Security teams should also monitor their print servers for unusual activity or unauthorized access logs that may indicate a prior breach. While the emergency patches address the immediate threat for the latest versions, administrators on older builds should seek further guidance from PaperCut to ensure their environments are fully secured.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.