PaperCut NG and MF actively exploited zero-day security flaw
Vulnerability
Summary
Hide ▲
Show ▼
PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk. The vendor has issued emergency patches and urged administrators to restrict web access to trusted IP addresses.
Related Happenings
PaperCut customer confirmed compromise incidents
Incident
H score36
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
How related:
We are aware of confirmed customer incidents and are treating this matter with the highest priority.
About this happening:
PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...
PaperCut customer confirmed compromise incidents
IncidentHow related: We are aware of confirmed customer incidents and are treating this matter with the highest priority.
About this happening: PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
Incident
H score26
First: 06.08.2026 21:22
Last: 06.08.2026 21:22
Sources 1
About this happening:
Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach
IncidentAbout this happening: Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score79
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveAbout this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Timeline
-
27.08.2026 19:31 2 articles · 3h ago
PaperCut warns of active zero-day exploitation in NG and MF
Initial DisclosurePaperCut says hackers are actively exploiting a vulnerability affecting all versions of PaperCut NG and PaperCut MF, and it is aware of confirmed customer incidents. The company urges organizations with Internet-exposed PaperCut Application Servers to restrict web access to trusted IP addresses, has released emergency patches for public-facing PaperCut NG/MF servers, and shared indicators of compromise including suspicious activity from the legitimate pc-app.exe process and server.log files that have been modified, deleted, or are missing.
Show sources
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — www.bleepingcomputer.com — 27.08.2026 19:31