PaperCut confirmed active exploitation of two chained vulnerabilities in PaperCut NG and MF on August 27, 2026, then shipped emergency patches for versions 25, 26, and 24 within about a day. Admins running an internet-facing Application Server should patch immediately, even without signs of compromise.

Read the full story: PaperCut Rushes Emergency Patches After Confirmed Attacks →

Transcript

PaperCut just confirmed real attacks against its print management software, and it moved fast. Two vulnerabilities, chained together: the first skips authentication in the web console, the second turns that access into arbitrary code execution. Security firm Huntress already caught attackers running recon commands on live customer systems. PaperCut shipped emergency patches within about a day, covering three separate branches. Here's why this matters beyond the CVSS scores: PaperCut had almost this exact scenario in 2023, when ransomware crews used a similar flaw to hit schools and universities. Print servers run privileged, sit deep in networks, and get patched last. If you're running an internet facing PaperCut server, patch it today.