Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Zero‑Day Vulnerability in PaperCut NG & MF Print Management Software Actively Exploited

PaperCut reports a zero‑day flaw in its NG and MF print‑management suites that attackers are exploiting in the wild. The incident highlights the need for continuous third‑party patch monitoring to satisfy SOC 2 change‑management and vulnerability‑management controls.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Zero‑Day Vulnerability in PaperCut NG & MF Print Management Software Actively Exploited

What Happened — PaperCut disclosed that a zero‑day flaw affecting all versions of its PaperCut NG and PaperCut MF print‑management suites is being weaponised in the wild. The vendor issued emergency patches for the v25 and v26 branches and confirmed that at least one customer has been impacted.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a control‑gap scenario that SOC 2 Change Management (CC6.1) and Vulnerability Management (CC7.2) are designed to detect, remediate, and evidence.
  • Continuous evidence of third‑party patching and remediation is essential to demonstrate due diligence during a SOC 2 audit.
  • Mapping this vulnerability to your control framework and retaining audit‑ready proof of remediation reduces audit‑finding risk and supports a defensible trust posture.

Who Is Affected — Organizations that rely on PaperCut NG or MF for print management across any sector (e.g., education, healthcare, finance, and enterprise IT).

Recommended Actions

  • Immediately apply the emergency patches for v25/v26 and verify that all endpoints are updated.
  • Record patch‑deployment dates, affected assets, and validation results in a centralized compliance repository.
  • Integrate PaperCut into your continuous vulnerability‑scanning program and map the finding to SOC 2 CC6.1/CC7.2 controls.
  • Update incident‑response playbooks to include print‑service exploitation scenarios.

Technical Notes — The flaw is a remote code execution (RCE) path triggered via malformed print‑job data; no CVE ID has been published yet. Attackers are exploiting it over the network to gain execution on print‑server hosts. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →