Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Active Exploitation of Unnamed Zero‑Day in PaperCut NG/MF Print‑Management Software Prompts Emergency Patch

PaperCut reports that a zero‑day vulnerability in its NG and MF products is being actively exploited. The vendor has issued emergency patches and advises immediate network‑access restrictions. This underscores the need for continuous vulnerability monitoring and documented remediation for audit readiness.

LiveThreat™ Intelligence · 📅 August 30, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Active Exploitation of Unnamed Zero‑Day in PaperCut NG/MF Print‑Management Software Prompts Emergency Patch

What Happened – PaperCut Software disclosed that a previously unknown zero‑day vulnerability in its NG and MF print‑management products is being actively exploited. The company issued emergency patches and urged customers to apply them immediately and to block internet‑facing access to the application servers.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of unpatched critical flaws and the need for continuous vulnerability‑management evidence.
  • Highlights the importance of network‑access controls that restrict public‑internet exposure of privileged application servers.
  • Aligns with the control objective of timely remediation and documented proof of mitigation, which feeds audit‑readiness across multiple frameworks.

Who Is Affected – Organizations that deploy PaperCut NG or MF, spanning education, health, government, and enterprise IT environments (primarily SaaS/On‑prem print‑management customers).

Recommended Actions – Apply the emergency patches without delay, enforce firewall or network‑access‑control rules to allow only trusted IP ranges, and capture remediation evidence in your continuous control‑assurance platform.

Technical Notes – The vulnerability has no public CVE yet; indicators include suspicious activity from pc‑app.exe and tampering with server.log entries such as “ERROR No suitable driver found for jdbc:no:x”. The attack vector is a direct exploit of the software flaw, followed by log manipulation to evade detection.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197980/hacking/papercut-zero-day-under-active-attack-emergency-patch-released.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →