PaperCut says attackers are exploiting flaws in PaperCut NG and MF. Organizations should restrict public access immediately, check for signs of intrusion, and review the emergency patch.
In 60 seconds
- PaperCut says every version of PaperCut NG and MF should be treated as potentially affected.
- If the server is reachable from the internet, restrict access to trusted addresses immediately.
- Emergency Patch Release 3 supersedes earlier releases for versions 24, 25, and 26.
- IT should check PaperCut’s listed signs of intrusion, even after installing the patch.
Who should care
This is for any organization that uses PaperCut NG or PaperCut MF to manage printing, especially one with an internet-facing Application Server. A home computer that does not run PaperCut server software is not the audience for this alert.
PaperCut says all NG and MF versions should be considered potentially affected. CISA added two related flaws to its list of security weaknesses attackers are known to be using. PaperCut also says it has confirmed customer incidents and active exploitation.
What to do today
First, find out whether your organization runs PaperCut NG or MF and who manages it. If the server can be reached directly from the public internet, PaperCut says to restrict access immediately to trusted internet addresses. Do not wait for a routine maintenance window to make that access change.
PaperCut has released Emergency Patch Release 3 for versions 24, 25, and 26. PaperCut says Release 3 supersedes the earlier emergency releases, and customers on earlier versions should follow its guidance to upgrade to the latest version. The person responsible for the server should read the current bulletin, confirm the installed version, and follow the matching official update instructions.
A patch is not the whole check
PaperCut tells customers to look for listed signs that someone may already have entered the server. That matters because installing an update closes a known door but does not remove an intruder who arrived earlier.
The review belongs with the IT provider or staff member who can examine PaperCut logs, server activity, accounts, and network exposure. If anything unusual appears, preserve the evidence and follow the organization’s incident-response process before making broad cleanup changes.
What remains in progress
PaperCut says its investigation is continuing and that its bulletin may change as it learns more. Organizations should use the bulletin itself as the working source, rather than relying on a screenshot, social post, or an older summary.
The urgent point is practical: identify the server, remove unnecessary public exposure, apply the correct official update, and check whether the system shows signs of earlier access.
Does this affect me?
- Who may be affected
- Any organization using PaperCut NG or MF should act, especially if its Application Server is internet-facing. PaperCut says all versions should be considered potentially affected.
- How to check
- Ask whoever manages printing or IT whether PaperCut NG or MF is installed, which version it runs, and whether the server is reachable from the public internet.
- What to do
- Restrict public access to trusted addresses, review PaperCut’s Emergency Patch Release 3 guidance, and check the vendor’s listed signs of intrusion.
- What to avoid
- Do not download fixes from an email or unofficial site, expose the server for convenience, or assume installing a patch proves no earlier access occurred.
Common questions
Does this matter if we only use ordinary desktop printers?
Not by itself. This alert is about organizations running PaperCut NG or MF server software, not every printer or home computer.
Which PaperCut versions are affected?
PaperCut says all PaperCut NG and MF versions should be considered potentially affected. Emergency Patch Release 3 supersedes the earlier releases for versions 24, 25, and 26; customers on earlier versions should follow PaperCut’s guidance to upgrade to the latest version.
Is installing the emergency patch enough?
It is an important step, but PaperCut also tells customers to restrict public access and check its listed signs of intrusion because an attacker may have arrived before the update.
Who should handle this?
The person or provider responsible for the PaperCut server, network access, logs, and incident response should handle it. General staff should not install a fix from an unsolicited link.
Primary source
Sources: CISA’s August 31 catalog update and PaperCut’s August 27 urgent security bulletin, which PaperCut has continued to update with affected-version, patch, and investigation guidance. Read the complete original source.
More reporting on this event
Need help deciding what this means for your business?
Leon can help identify the affected systems and a proportionate next step.
Article history: Updated Sep 1, 2026: Added PaperCut’s affected-version scope, immediate internet-access restriction, Emergency Patch Release 3 guidance, and investigation steps.
