As cited
Copy frozen at (site build).
vulnerabilities
Attackers plant remote access tools on compromised PaperCut servers
Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing PaperCut Application Servers. The vendor disclosed the ongoing campaign on August 27, 2026, and subsequently identified the secondary payload deployment activity. Organizations running vulnerable PaperCut NG and MF print management solutions remain at risk of unauthorized remote access.
Why it matters: Administrators of PaperCut NG and MF deployments need to immediately restrict web access and patch, as attackers are establishing persistent remote access to compromised servers, potentially enabling lateral movement or data exfiltration.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Attackers plant remote access tools on compromised PaperCut servers
Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing PaperCut Application Servers. The vendor disclosed the ongoing campaign on August 27, 2026, and subsequently identified the secondary payload deployment activity. Organizations running vulnerable PaperCut NG and MF print management solutions remain at risk of unauthorized remote access.
Why it matters: Administrators of PaperCut NG and MF deployments need to immediately restrict web access and patch, as attackers are establishing persistent remote access to compromised servers, potentially enabling lateral movement or data exfiltration.
- Source published
- First seen by Cybersecurity Tracker