Summary
On August 27, 2026, PaperCut issued an urgent security advisory confirming that a critical vulnerability in PaperCut NG and PaperCut MF is being actively exploited in the wild. This vulnerability allows an unauthenticated attacker to remotely execute code on any PaperCut Application Server. Meaning no login is required to take control of the system. All versions of PaperCut NG and PaperCut MF are considered affected. Huntress has observed confirmed exploitation in customer environments and has published a detailed technical analysis. Emergency patches are available for versions 25 and 26; a fix for version 24 is still in progress.
Am I Affected?
Any organization running PaperCut NG or PaperCut MF should treat this as urgent. To assess your exposure:
- Identify whether you have a PaperCut Application Server or Site Server running. If PaperCut is installed in your environment, you are in scope regardless of version.
- Check whether the PaperCut Application Server is accessible from the internet. If the management interface is reachable from outside your network, your risk is significantly elevated and immediate action is required.
- Review your PaperCut version. Emergency patches are available for versions 25 and 26. If you are on version 24 or earlier, a patch is not yet available — network isolation is your primary mitigation.
- Check for signs of compromise by reviewing the PaperCut
server.logfile for unexpected entries, missing or truncated log files, or unusual process activity originating from the PaperCut Application Server process.
What Is Huntress Doing?
- Actively monitoring all PaperCut installations across our partner base for signs of exploitation, including retroactive analysis of historical telemetry.
- Detection rules are live in the Huntress platform to identify suspicious activity associated with this vulnerability, including unusual process execution originating from the PaperCut Application Server.
- Coordinating directly with PaperCut to share technical findings and support their ongoing patch development efforts.
- Proactively reaching out to partners with PaperCut installations, particularly those with internet-facing servers, to ensure awareness and prompt action.
Recommended Next Steps
- Remove the PaperCut Application Server from public internet exposure immediately. Place it behind a firewall or VPN and restrict access to trusted IP addresses only. This is the single most impactful action you can take right now.
- Apply PaperCut's emergency update if you are running version 25 or 26. If you are on version 24 or earlier, network isolation is your primary mitigation until a patch is available.
- Preserve evidence before patching or restarting if the server was publicly exposed. Retain the full
server/logs/directory, current PaperCut configuration, and recent endpoint process and file activity. - Review PaperCut's investigation guidance in their security advisory for specific log entries and artifacts that may indicate compromise.
How to Get Help
For full technical details, investigation guidance, and indicators of compromise, refer to the Huntress blog post covering this incident: huntress.com/blog/papercut-actively-exploited
PaperCut's official security advisory is available at: papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory
If you have questions or believe you are affected, please reach out to Huntress Support — we are here to help.