Executive Summary

Threat actors are actively exploiting PaperCut Application Servers to deploy remote access tools. This campaign affects PaperCut NG and MF print management solutions and is considered highly severe due to the potential for remote code execution and lateral movement.

Technical Analysis

The threat actor is targeting internet-facing PaperCut Application Servers, exploiting zero-day vulnerabilities to covertly install legitimate remote access software. The vendor, PaperCut Software, first warned of in-the-wild compromises on August 27, 2026, and urged customers to restrict web access to trusted IP addresses only.

How It Gets Exploited

An attacker with access to an internet-facing PaperCut Application Server can exploit the zero-day vulnerability to deploy remote access tools. The attacker likely uses a web-based interface to trigger the vulnerability, potentially by sending a crafted request to the server. Once exploited, the attacker can install legitimate remote access software, allowing them to maintain access to the compromised server.

Impact Assessment

PaperCut NG and MF print management solutions are affected by this campaign. If exploited, an attacker can achieve remote code execution, potentially leading to lateral movement within the network. The blast radius is considered high, as an attacker can use the deployed remote access tools to pivot to other systems.

Recommended Actions

  • Immediately restrict web access to trusted IP addresses only, as recommended by PaperCut Software.
  • Monitor for suspicious activity on PaperCut Application Servers, such as unusual login attempts or software installations.
  • Implement a web application firewall (WAF) to detect and block suspicious traffic.
  • Ensure that all PaperCut Application Servers are running with the latest security patches and updates.

Sources