Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut NG and MF actively exploited zero-day security flaw

Vulnerability
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

PaperCut NG and PaperCut MF are facing active zero-day exploitation across all versions, putting Internet-exposed application servers at immediate compromise risk. The vendor has issued emergency patches and urged administrators to restrict web access to trusted IP addresses.

Related Happenings

PaperCut customer confirmed compromise incidents

Incident
H score36 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: We are aware of confirmed customer incidents and are treating this matter with the highest priority.

About this happening: PaperCut customers are facing confirmed compromise incidents tied to actively exploited PaperCut NG and PaperCut MF servers, putting exposed deployments at immedia...

Federal Office for Information Technology and Telecommunication (BIT) hit by data theft breach

Incident
H score26 First: 06.08.2026 21:22 Last: 06.08.2026 21:22 Sources 1

About this happening: Switzerland’s Federal Office for Information Technology and Telecommunication (BIT) confirmed a breach of its Microsoft SharePoint servers that compromised about 200 acc...

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score79 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Timeline

  1. 27.08.2026 19:31 2 articles · 3h ago

    PaperCut warns of active zero-day exploitation in NG and MF

    Initial Disclosure

    PaperCut says hackers are actively exploiting a vulnerability affecting all versions of PaperCut NG and PaperCut MF, and it is aware of confirmed customer incidents. The company urges organizations with Internet-exposed PaperCut Application Servers to restrict web access to trusted IP addresses, has released emergency patches for public-facing PaperCut NG/MF servers, and shared indicators of compromise including suspicious activity from the legitimate pc-app.exe process and server.log files that have been modified, deleted, or are missing.

    Show sources