
PaperCut Issues Emergency Patch for Actively Exploited Zero-Day Vulnerability in NG/MF Print Management Software
PaperCut has released an urgent security update for a zero-day vulnerability in its NG/MF software currently under active exploitation, posing a critical risk to enterprise print environments.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Mandiant
- Read Time:
- 4 min
Executive Summary
On August 28, 2026, PaperCut released an emergency security advisory regarding a critical zero-day vulnerability affecting its NG and MF print management solutions. The vulnerability, which has not yet been assigned a formal CVE identifier, is reportedly being exploited in the wild to gain unauthorized access to print servers. Given the ubiquity of PaperCut in educational, governmental, and corporate sectors, the threat level is categorized as Critical. Encrygma analysts recommend immediate patching to the latest version (v26.1.3 or higher) to mitigate the risk of full system compromise, as reported by SecurityWeek.
Threat Analysis
The exploitation of print management software has become a recurring theme for both state-sponsored actors and ransomware groups. By compromising a print server, attackers can bypass traditional perimeter defenses and establish a foothold within the internal network. This specific zero-day allows for remote code execution (RCE) without requiring user interaction, making it a highly desirable asset for initial access brokers. Current telemetry suggests that the exploit is being used in targeted attacks against North American and European infrastructure, mirroring recent trends seen in the exploitation of Microsoft Exchange and Citrix NetScaler vulnerabilities earlier this month.
Technical Details
While specific technical details are being withheld to prevent further exploitation, the vulnerability appears to reside in the Application Server component of PaperCut NG/MF. Preliminary analysis indicates an improper input validation flaw that leads to a memory corruption event. Attackers can send specially crafted packets to the server's listening port (typically 9191 or 9192) to trigger the flaw. Once triggered, the attacker can execute arbitrary commands with the privileges of the PaperCut service, which often runs with SYSTEM or administrative rights. This follows a pattern of "living-off-the-land" techniques where legitimate management tools are turned against the host, similar to the afd.sys kernel driver exploit (CVE-2026-68820) identified in the August 2026 Patch Tuesday.
Attribution Assessment
At this stage, attribution remains unconfirmed. However, the sophistication of the exploit and the speed at which it was deployed suggest a well-resourced threat actor. Encrygma is monitoring activity patterns that align with known cybercriminal groups and APTs that have historically targeted print spoolers for lateral movement. The Kremlin-linked actors recently observed exploiting Exchange Server flaws, as noted by Proofpoint, are also under scrutiny for potential involvement in this campaign.
Implications
The implications of a successful compromise are severe. Beyond the immediate loss of print services, attackers can exfiltrate sensitive documents stored in print queues, harvest credentials from the server's memory, and move laterally to domain controllers. In many environments, print servers are poorly segmented, providing a direct path to the core of the network. If left unpatched, this vulnerability could serve as a primary entry point for large-scale ransomware deployments.
Recommendations
Encrygma recommends that organizations immediately update PaperCut NG/MF to the latest security release. Furthermore, administrators should isolate print servers into a dedicated VLAN with restricted access to and from the rest of the network. Review Application Server logs for unusual connections on ports 9191/9192 and unauthorized service restarts. If web-based print management is not required externally, ensure it is blocked at the firewall to reduce the attack surface.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
