PaperCut NG/MF Critical Zero-Day Exploited in the Wild
What happened
PaperCut Software confirmed active exploitation of an unpatched authentication bypass in PaperCut NG and MF, which allows attackers to execute malicious SQL and achieve remote code execution. The vendor released emergency patches for versions 25 and 26 on August 28, 2026, and advises administrators to immediately restrict web access to trusted internal IP ranges.
Why it ranks #1
PaperCut NG and MF face active exploitation of an unpatched authentication bypass enabling SQL injection and remote code execution, prompting emergency vendor patches and immediate network access restrictions.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Prioritize emergency patching for PaperCut NG or MF, especially when the Application Server is accessible from the public internet.
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited