The vendor confirms ongoing attacks against every version of PaperCut

PaperCut confirmed on 28 August 2026 that a vulnerability in PaperCut NG and PaperCut MF is being exploited. The confirmation followed investigations by the company's own security response team into reported incidents, and every version is affected. Emergency patches for versions 25 and 26 were released on 28 August, and a patch for version 24 is in progress. The vendor asks administrators to restrict the Application Server web interfaces to trusted IP addresses immediately if they are reachable from the internet.

The advisory lists what to look for. Suspicious post-exploitation activity from pc-app.exe is one sign, and a server.log file that is missing or altered is another. PaperCut also gives two error strings to search for. The company stresses that the absence of these indicators does not rule out compromise.

What this means for you if you run the print server

A print server is the kind of system that simply stays. It was set up when somebody needed control over printing, it often has a route out to the internet so staff can print from home, and it rarely appears on the list of what gets monitored. Our assessment is that this is exactly why such servers become targets. An attacker is not looking for important systems, but for open ones.

The order in the advisory is worth following as it stands. Closing the interface to the internet takes minutes, and it works whichever version you run. The patch takes longer, and for version 24 it does not exist yet. If you are on version 24, closing the interface is all you have right now, so search the logs at the same time rather than waiting.

Berigo recommends

  • Close the Application Server web interface to the internet today, and admit only trusted addresses.
  • Look up which version you run, and install the emergency patch if you are on version 25 or 26.
  • Search for the traces the vendor describes, and remember that their absence does not clear the server.
  • Secure the logs off the server itself, so an attacker cannot alter them where they are written.
  • Set a date for version 24, and follow when the patch arrives.

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch