Threat Intelligence

Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login

The Hacker News · 29 Aug 2026
Key Takeaway If your business uses PaperCut NG or MF, apply the latest emergency patch immediately and ensure the print server isn't unnecessarily exposed to the internet.

Security researchers have found that malicious actors are actively exploiting a newly patched flaw in PaperCut NG and MF, popular print management software used by businesses worldwide. The vulnerability allows an unauthenticated attacker to remotely take control of PaperCut's trusted configuration settings, which can then be abused to run arbitrary Java code inside the application. In response, PaperCut has released an emergency fix that adds further hardening beyond the initial patch.

This type of vulnerability chain is particularly dangerous because it removes the need for stolen passwords or insider access — an attacker simply needs network access to a vulnerable, internet-facing PaperCut server to gain a foothold. Once inside, attackers could potentially deploy further malware, steal data, or move deeper into a company's network.

Any business using PaperCut NG or MF for print management should treat this as a high-priority update. Given that PaperCut is widely deployed in offices, schools, and government agencies, unpatched systems represent an attractive and easy target for opportunistic attackers scanning the internet for vulnerable servers.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.