Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

PaperCut Zero‑Day Exploited in NG/MF Print Management Products – Emergency Patch Issued

PaperCut disclosed active exploitation of a zero‑day flaw in its NG and MF print‑management servers and released emergency patches. The event highlights the need for robust change‑management and continuous evidence of patching to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

PaperCut Zero‑Day Exploited in NG/MF Print Management Products – Emergency Patch Issued

What Happened — PaperCut Software disclosed that a previously unknown zero‑day vulnerability in its NG and MF print‑management applications is being actively exploited. The vendor released emergency patches on Friday and warned customers to isolate the application servers from the public Internet.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a control gap in Change Management and System Operations (SOC 2 CC6.1/CC3.1) where unpatched software can become an attack vector.
  • Continuous evidence of patch‑management, network‑segmentation, and firewall rule enforcement is essential to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s Control Mapping capability can automatically map the emergency‑patch process to the relevant SOC 2 controls and collect immutable proof for auditors.

Who Is Affected — Organizations that deploy PaperCut NG/MF for print management across any sector (education, health, finance, government, etc.).

Recommended Actions

  • Apply the emergency patches immediately.
  • Restrict PaperCut application‑server web access to trusted IP ranges via firewall or network‑access‑control lists.
  • Document the patch‑deployment workflow and update your change‑management records to reflect the emergency response.
  • Enable continuous monitoring of the server logs for the IOC patterns listed in the advisory.

Source: Security Affairs

Technical Notes

  • No CVE identifier assigned yet; the flaw affects PaperCut NG and MF servers.
  • Attackers have been observed deleting or truncating server.log entries and injecting malformed JDBC error strings.
  • Indicators of compromise include suspicious activity from pc‑app.exe and log entries such as ERROR No suitable driver found for jdbc:no:x.
📰 Original Source
https://securityaffairs.com/197980/uncategorized/papercut-zero-day-under-active-attack-emergency-patch-released.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →