PaperCut Patched Twice More After Its First Emergency Fix Failed

IMAGES-4 (18)Nobody updates a print server unless printing breaks. Automatic patching covers Windows, and maybe the firewall. Print management is rarely on that list. And if it ain’t broke, don’t fix it. So if you run PaperCut, it is probably on whatever version it was on last month.
 

PaperCut’s first emergency fix a few days ago needed another emergency fix, and then another. A pattern is forming here, and PaperCut is not the only one in it.

On August 27 the company told customers that attackers were already inside some of their own print servers. It shipped the first patch the following day, and researchers penetrated that fix within hours. A second patch followed that same afternoon, and a third arrived on September 1. PaperCut now says anyone who applied the first or second patch is still not fully protected. The United States cybersecurity agency added both flaws to its list of known vulnerabilities under active attack, and federal agencies have until September 14 to close that actively exploited security gap. Both can be patched now on versions 24, 25 and 26. There is no patch for version 23 or older, and the only route there is to upgrade first.

On August 31 the Shadowserver Foundation counted at least 204 PaperCut servers on the internet still missing the fix. It advised anyone running a PaperCut server to consider it already breached. PaperCut says most of its customers were behind a firewall or already patched, so the exposed group is small, and the whole question is whether you are in it.

PaperCut has since reported a second wave against servers that are still unpatched and still reachable from the internet, and says the behaviour after break-in is more sophisticated than the initial attacks. PaperCut documented cases where attackers installed the remote support tool SimpleHelp as a Windows service named Remote Access Service, then downloaded AnyDesk to establish persistence. Both are ordinary administration tools. And once they are running, nothing on that server looks like an attack, which is why PaperCut tells customers to go looking for those by name. If a server was reachable from the internet and unpatched, that check is worth doing before anything else, because patching closes the first security gap and not the second. A remote access tool left behind keeps working on a patched server, and PaperCut’s advice for a server it believes is compromised is to rebuild it from a clean backup rather than update it.

Patches can leave people with a false sense of protection, especially where firewalls or critical business infrastructure exist. An update can install cleanly, update the version, and you click Finished on the installer thinking you are good to go, yet the server can still be perfectly exploitable, because that installed version needed to be patched two more times before the vendor was able to close the complex security gap. We will see this happen again.

And listen, this isn’t just about print servers. Earlier in August, N-able said an authentication bypass in its N-central platform originated in an incomplete patch for a prior flaw, and attackers were already exploiting it. When OWASP launched a project on August 26 to generate automated fixes for open-source software, they stated the reason: flaws are found faster than maintainers can close them. A vendor under that pressure will sometimes ship a fix that doesn’t close the security gap.

Three things are worth doing this week, and none of them need you to be technical. First, if your company uses it, then find out where PaperCut is actually running. That is the hard part for most businesses, because print management does not always run on a machine anyone calls a print server.

Then check the version on each of those servers against PaperCut’s security bulletin, which lists the fixed build number for every version of NG and MF. Site servers and secondary print servers count too, not only the main one. Mobility Print, Print Deploy and the client software are not affected, and neither are PaperCut Hive or Pocket. Then find out which of them can be reached from the open internet, because PaperCut’s own advice for machines it cannot fix yet is to restrict their access to a whitelist.

One rule to remember: the security gap closes on a version number. Subject to change.

NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.

Source: PaperCut NG/MF Security Bulletin, 27 August 2026, updated continuously. https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/