PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
Cybersecurity Classified by Officially
In an August 27 security advisory, PaperCut said attackers are actively exploiting a pre-authentication remote code execution vulnerability against PaperCut NG and PaperCut MF, with confirmed customer incidents.
Huntress has found evidence of exploitation in two customer environments. Observed activity focused on system discovery. We have not observed secondary malware, further command-and-control traffic, or additional persistence or post-exploitation from the recovered payload.
Huntress reproduced a full pre-authentication RCE chain against a vanilla PaperCut NG 25.0.11.75758 server. We have reached out to PaperCut to coordinate with them on continued vulnerability analysis.
On September 10, PaperCut released regular maintenance releases for PaperCut NG and PaperCut MF (26.0.5, 25.0.13, and 24.1.10) that address these issues. If you previously installed an emergency release, upgrade to the latest maintenance release for your version. Whether or not you can patch immediately, it is strongly recommended to remove the application server from public-facing internet connections and limit access to trusted networks.
Acknowledgements: Special thanks to Tanner Filip, Jai Minton, Max Rogers, Ben Nahorney, Lindsey Welch, Susannah Matt, Aaron Deal, Dray Agha, Lindon Wass, Michael Elford, and Craig Sweeney for their contributions to this investigation and writeup.
Update: 9/10/26 @ 12:20 PM ET
PaperCut has released regular maintenance releases for PaperCut NG and PaperCut MF: 26.0.5, 25.0.13, and 24.1.10. The maintenance releases replace the emergency patch builds 1, 2 and 3. If you installed an emergency patch, PaperCut recommends moving to the appropriate maintenance release.
If you have not yet patched, upgrade now and review the release notes for your product and version before proceeding.
Find the latest version for your environment on the PaperCut product upgrade page.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/papercut-actively-exploited
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/papercut-actively-exploited