Key Takeaway
- 🚨 Déjà Vu: A new PaperCut zero-day is under active exploitation, and this time the company has confirmed customer incidents — all versions of PaperCut NG and MF are affected until patched.
- 🖨️ Print Servers Are the Prize: The same weaknesses that made PaperCut the most abused print platform of 2023 — elevated privileges, broad network access, forgotten maintenance — have not changed.
- 🔒 Details Withheld: PaperCut released an emergency patch and a second follow-up fix but is withholding technical specifics to slow copycat attackers.
- 🖥️ Act Before Monday: Patch now, firewall the print server’s web interface to trusted IPs only, and check the published indicators of compromise — exposed servers are being probed continuously.
PaperCut zero-day attacks have returned, and the parallels to 2023 are not subtle. This new PaperCut zero-day arrives with something the 2023 disclosure never had at launch: confirmed victims. Three years ago, CVE-2023-27350 turned Print Management software into one of the most productive ransomware footholds ever measured, exploited by the Clop-affiliated Lace Tempest crew, by LockBit, by Iranian state-linked groups, and by the Bl00dy gang as they tore through hundreds of organizations. Now PaperCut Software’s security response team is once again investigating active exploitation of a vulnerability affecting all versions of PaperCut NG and PaperCut MF, with confirmed customer incidents already on the record and an emergency patch issued for public-facing servers. The company is deliberately withholding technical exploit details, but the shape of the response — emergency patch, follow-up fix, indicators of compromise, urgent firewall guidance — tells IT teams everything essential about severity.
The question every network administrator should be asking is not whether this will spread, but how quickly the ransomware ecosystem picks it up. In 2023 the gap between disclosure and mass exploitation was measured in days. This time, attackers already have confirmed victim organizations, a live target map, and vendor confirmation that exploitation works — all before most administrators have read the advisory. That inversion of the usual timeline is why this incident deserves attention this weekend, not at the next patch cycle.
What We Know About the 2026 PaperCut Zero-Day
The confirmed PaperCut zero-day facts come from the company’s own security bulletin and follow-up reporting. The vulnerability affects every version of the two flagship products — PaperCut NG, the on-premise print management platform, and PaperCut MF, its multifunction-device variant used across schools, enterprises, and managed print vendors worldwide. Exploitation of the PaperCut zero-day is not theoretical: the company’s advisory states plainly that it is “aware of confirmed customer incidents and is treating this matter with the highest priority.” A first emergency patch was released for customers running public-facing PaperCut servers, and a second emergency patch followed days later as the investigation widened — a sequence that suggests the original fix did not close every attack path, which is itself a signal worth reading.
PaperCut has withheld the technical mechanics: no CVE number at publication, no exploit detail, no vulnerable-endpoint disclosure. The company’s reasoning is defensible — publishing a working exploit recipe while attacks are ongoing would hand every opportunistic crew a turnkey weapon — but the silence also means defenders cannot build precise detections themselves. What PaperCut has published instead are indicators of compromise and a mitigation priority list: restrict the web interfaces of any internet-exposed PaperCut Application Server to trusted IP addresses immediately, using firewall rules or network access controls. That guidance is the operational heart of the advisory, because exposure is the variable that turns a dangerous bug into a mass event.
The company’s disclosure discipline deserves a note of credit here. Confirmed incidents were acknowledged early, patches shipped before full root-cause analysis was public, and the advisory was updated as verified information arrived. That is the responsible order of operations under active exploitation — speed on fixes, caution on details, transparency on indicators. It mirrors the disclosure pattern the wider industry settled on after years of supply-chain incidents, the same pattern we analyzed in the Hugging Face attack postmortem: publish what defenders need, withhold what attackers want.
The 2023 Playbook: Why Security Teams Feel the Déjà Vu
To understand the stakes, rewind to April 2023. PaperCut servers worldwide began getting hit through CVE-2023-27350, an improper access control flaw in the product’s SetupCompleted class that allowed an unauthenticated attacker to bypass login entirely and execute code with SYSTEM privileges — the highest authority Windows offers. Microsoft attributed the campaign to Lace Tempest, a financially motivated group operating as a Clop ransomware affiliate with a history at GoAnywhere and a taste for the Raspberry Robin loader. Within weeks, the exploitation had spread to LockBit and other crews, and victims ranged across education, government, and private enterprise in dozens of countries.
The 2023 post-mortems converged on two uncomfortable truths. First, print management software is a nearly perfect intrusion target: it runs with elevated privileges, it talks to everything on the network, it holds stored credentials for print and directory services, and almost nobody includes it in vulnerability management. Print servers are infrastructure’s attic — everyone knows something is up there, few people ever look. Second, once one crew proves a bug’s value, the commoditization is instant: exploit kits spread through affiliate channels within days, and patching statistics from that period showed unpatched PaperCut servers lingering for months even after the emergency patch. The lesson of 2023 was not that PaperCut was careless; it was that any internet-exposed management interface on an enterprise appliance will eventually meet a criminal supply chain optimized to reach it.
That is the pattern repeating now: a confirmed zero-day in a widely deployed administrative platform, exploitation already in progress, and a vendor racing to patch while withholding the details attackers would love. The difference in 2026 is that everyone watching remembers where this story went last time.
Why Print Servers Keep Getting Hacked
Print infrastructure occupies a strange position in enterprise security.
It is critical enough to run with high privileges, forgotten enough to run unpatched for years. PaperCut servers typically hold domain credentials for pulling user directories, integrate with badge systems and payment platforms at schools and offices, and expose web dashboards designed for convenience. They sit on networks where they can talk to file servers, identity systems, and user endpoints; once an attacker achieves code execution there, lateral movement is not a separate step — it is the default environment. That is why print-server compromise in 2023 so quickly became ransomware deployment rather than a curiosity.
The structural exposure compounds the technical one. Organizations large and small — including the Philippine enterprises, universities, LGUs, and BPOs that make up much of our regional economy — routinely print in the clear on public IPs because Remote work-era access made dashboards convenient. Every exposed instance is discoverable by trivial internet-wide scanning, and the economics of ransomware ensure that discovery is immediate: the 2023 exploitation wave demonstrated that hundreds of organizations can be compromised from a single disclosed flaw before most administrators finish their coffee. Our reporting on ASEAN’s record data breach costs puts hard numbers on what that discovery window costs the region’s organizations — and print servers rarely appear in anyone’s budget line until they appear in an incident report instead.
What Network and IT Teams Should Do This Weekend
The response ladder is short, and the first two rungs matter most. Patch immediately.
Apply the emergency releases from PaperCut’s security bulletins page to every NG and MF instance, keeping in mind that a second patch followed the first and both are required. Segregate exposure at the same time: the mitigation PaperCut emphasizes is restricting each Application Server’s web interface to trusted IP addresses through firewall rules or access controls, and an internet-exposed print dashboard in 2026 should be treated the way we treat exposed databases — as an active incident until proven otherwise.
Then work the detection ladder. Check the published indicators of compromise against server logs and authentication records, hunt for unexpected process launches or service accounts on the print infrastructure, and if your PaperCut deployment supports it, review what user and directory integrations the underlying service account can reach. Assume-breach thinking applies here: if a paper trail shows anything unusual — new scheduled tasks, odd outbound connections, unexplained credential prompts — escalate to incident response while the trail is warm. Teams that cannot patch this weekend should firewall aggressively and disable public access entirely, because the 2023 experience showed that exploitation against known-unpatched servers follows the advisory within days, not weeks.
The organizational lesson runs deeper than one product. Print management, badge systems, IP cameras, building controls — the administrative layer of every network is exactly where attackers concentrate, because that layer is maintained least and trusted most. The same reasoning we applied to the Oracle WebLogic emergency patch applies here: infrastructure that authenticates users and executes code on behalf of the network is the modern castle gate, and treating it as a set-and-forget appliance is how the 2023 playbook keeps working.
What Comes Next: The Ransomware Economy Meets PaperCut
Watch three developments in the coming weeks as the PaperCut zero-day story matures. First, watch for a CVE assignment and technical disclosure — once the patched versions are widely deployed, PaperCut and independent researchers will publish the PaperCut zero-day mechanics, and the exploit will enter every commodity scanning tool within roughly a week of that publication. Second, watch for the first ransomware claims referencing PaperCut intrusion infrastructure; given confirmed incidents already exist, initial access brokers are likely already monetizing whatever they hold. Third, watch how many exposed servers remain unpatched: internet-wide scanning studies after the 2023 incident found the long tail of unpatched systems stretching for months, and there is no reason to expect 2026’s discipline to be better. The organizations that escape this cycle will be the ones that treated the first bulletin as the final warning rather than the opening offer.
For Filipino IT teams, the PaperCut zero-day calculus includes one more factor: enterprise security budgets in the region are under the pressure documented in our ASEAN breach-cost analysis, and forgotten infrastructure like print servers never makes the funding proposal until it makes the news. The remediation for this incident costs an afternoon of one engineer’s time. The alternative — forensic investigation, ransom negotiation, downtime across every department that printed through the server — costs orders of magnitude more, and the 2023 experience says the invoice arrives within weeks of disclosure, not months.
Frequently Asked Questions About the PaperCut Zero-Day
What is the 2026 PaperCut zero-day?
It is a vulnerability under active exploitation that affects all versions of PaperCut NG and PaperCut MF print management software. PaperCut has confirmed customer incidents, released an emergency patch for public-facing servers and a second follow-up patch, and is withholding technical exploit details while its investigation continues. Indicators of compromise are published on the company’s security bulletins page.
Which PaperCut products and versions are affected?
All versions of PaperCut NG and PaperCut MF are affected until patched, according to the vendor’s advisory. The company urges any organization whose Application Server is exposed to the internet to restrict its web interface to trusted IP addresses immediately, using firewall rules or network access controls, in addition to applying the emergency patches.
Is my print server at risk if it is not internet-exposed?
Direct internet exposure is the highest-risk configuration, and it is the one PaperCut’s emergency guidance targets first. Internal print servers are not immune — lateral movement from other compromised hosts remains possible — but the confirmed incidents and urgent guidance center on public-facing deployments. If your PaperCut dashboard is reachable from the internet, treat patching and firewalling as same-day work.
How is this different from the 2023 PaperCut attacks?
The 2023 campaign exploited CVE-2023-27350, a logged improper access control flaw that allowed unauthenticated code execution with SYSTEM privileges and was used by Clop-linked Lace Tempest, LockBit, and Iran-linked groups. The 2026 incident’s technical details are intentionally undisclosed, but the response shape — emergency patching, confirmed victims, firewall guidance, published IOCs — matches the severity pattern of the 2023 disclosure that became a ransomware wave.
Where can I find the patch and indicators of compromise?
PaperCut maintains a security bulletins page at papercut.com/kb/Main/SecurityBulletins with the emergency patches, remediation guidance, and published indicators of compromise. Independent tracking is available from outlets including BleepingComputer and SecurityAffairs’ PaperCut zero-day coverage, which have followed both the 2023 and 2026 campaigns.
What should small organizations with one print server do first?
Three steps in this order: confirm your PaperCut server is not reachable from the public internet and firewall it if it is; apply both emergency patches from the vendor’s bulletin page; and review authentication logs against the published indicators of compromise. Organizations without in-house security staff should document their timeline and preserve logs in case formal incident support becomes necessary.
Financial Disclaimer: This analysis is based on PaperCut’s published security bulletin and independent security reporting. It is general information, not a substitute for professional incident response; organizations suspecting compromise should engage qualified security practitioners immediately.






