CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers plant remote access tools on compromised PaperCut servers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5420

As cited

Copy frozen at (site build).

vulnerabilities

Attackers plant remote access tools on compromised PaperCut servers

Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing PaperCut Application Servers. The vendor disclosed the ongoing campaign on August 27, 2026, and subsequently identified the secondary payload deployment activity. Organizations running vulnerable PaperCut NG and MF print management solutions remain at risk of unauthorized remote access.

Why it matters: Administrators of PaperCut NG and MF deployments need to immediately restrict web access and patch, as attackers are establishing persistent remote access to compromised servers, potentially enabling lateral movement or data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers plant remote access tools on compromised PaperCut servers

Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing PaperCut Application Servers. The vendor disclosed the ongoing campaign on August 27, 2026, and subsequently identified the secondary payload deployment activity. Organizations running vulnerable PaperCut NG and MF print management solutions remain at risk of unauthorized remote access.

Why it matters: Administrators of PaperCut NG and MF deployments need to immediately restrict web access and patch, as attackers are establishing persistent remote access to compromised servers, potentially enabling lateral movement or data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary