PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
Huntress, Friday, August 28th, 2026
Huntress reproduced a pre-authentication RCE chain in PaperCut NG/MF now under active exploitation, with patching guidance.
PaperCut disclosed in an August 27 security advisory that attackers are actively exploiting a pre-authentication remote code execution vulnerability in PaperCut NG and PaperCut MF.
Huntress researchers John Hammond and Andrew Brandt reproduced the pre-auth RCE chain and published their analysis.
The post provides urgent patching guidance along with advice on identifying exposure, since PaperCut servers are frequently internet-facing to support remote printing.
It also covers detection guidance for organizations that need to determine whether exploitation has already occurred in their environment rather than only closing the hole.