Choose your language

Choose your login

Support

URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)

THE PAGE APPLIES TO:

Last updated August 27, 2026

URGENT Security Advisory

PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.

We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing. We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.

Immediate action required

If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).

Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity.

Who is potentially impacted

This advisory applies to all versions of:

  • PaperCut NG
  • PaperCut MF

Indicators of compromise and investigation guidance

The following may be indicators of compromise:

  • Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from pc-app.exe.

  • Missing, unexpectedly truncated, or deleted PaperCut server.log files.

  • Any of the following entries in server.log:
    ERROR No suitable driver found for jdbc:no:x

    ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Important: The absence of the above indicators is not confirmation that a system has not been affected. PaperCut will publish validated, specific indicators and further guidance here as soon as they are available.

Current Status

Update

Details

Investigation progress

PaperCut’s security emergency response team has used information provided by a university customer’s security team and digital forensics and incident response team. This information has enabled PaperCut to reproduce a vulnerability in the PaperCut NG and PaperCut MF code.

Our emergency engineering team is developing and validating an appropriate code fix.

Security notifications

To stay informed about high impact security updates please subscribe to our Security notifications sign-up form.

Updates

Date

Update/action

27 August 2026 (AEST)

Published the initial Security Bulletin.

27 August 2026, 8:00pm (AEST)

Minor wording updates.

27 August 2026, 9:02pm (AEST)

Investigation update posted.




Category: Security Bulletins

Subcategory: Security and Privacy


Comments