Skip to content

Security1 publisher2 min readPublished

PaperCut escalated one education customer's compromised MF server to a zero-day P0 by midday

PaperCut's founder and CEO says the NG/MF incident is still open. Logs from two customers in the same region let his engineers rebuild most of the exploit chain, and the 2023 aftermath drove the order to unplug.

The Watch · Security desk

Illustration accompanying PaperCut escalated one education customer's compromised MF server to a zero-day P0 by midday

What happened

  • A report reached PaperCut at 9:42 a.m. AEST on Thursday 27 August 2026 from an education sector customer whose PaperCut MF server appeared to have been compromised.
  • By midday the company had declared a P0 incident and was working on the assumption of a previously unknown vulnerability being actively exploited in the wild.
  • A second organization in the same region reported similar activity at 5:05 p.m. that same Thursday afternoon.
  • PaperCut used its security alert systems to ask customers to temporarily take internet-facing Application Servers off the internet while it built a practical mitigation.
  • When that request went out, PaperCut did not yet understand the full exploit chain or know whether the technique had been shared between attacker groups.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The reachable surface is the internet-facing Application Server, and PaperCut puts the potentially exposed population in the thousands, so the count of servers still listening decides how large the next round can be.
  • precedent PaperCut's own 2023 sequence sets the expectation: the heaviest exploitation came after details circulated. The dangerous window for this bug opens when the chain becomes reproducible.
  • constraint Without a CVE, version list or indicators, an administrator cannot scope which of their servers are affected and is left with removal from the internet as the only decision available.
  • capability One customer's ability to isolate a virtual machine without wiping it is what gave the vendor an exploit chain to chase. Forensic readiness at the customer sits on the vendor's critical path.

Triage began with the ordinary question. PaperCut asked whether the education customer's server was fully patched, and looked at whether an attacker was using a vulnerability the vendor had already fixed in a later release [2]. The logs pointed to a different path and showed real code execution on the server [3]. That moved the working theory from n-day to zero-day in roughly two hours and eighteen minutes [18].

What the first customer handed over mattered because of how it was collected. Its intrusion-detection systems flagged the suspicious behaviour quickly and the affected virtual machine was isolated almost immediately, so logs and forensic evidence survived [7]. Those logs were thin: enough context to hint at an area of code that might be part of an exploit chain, which is what the engineering teams then tried to reproduce [5]. The second report arrived seven hours and twenty-three minutes after the first [17]. It came with additional logs and details, and with those PaperCut fingerprinted and reconstructed much more of the exploit chain and the attack [6].

The guidance to pull internet-facing Application Servers offline went out before any of that reconstruction was complete. "We assumed the worst and acted accordingly," wrote Chris, one of PaperCut's founders and its CEO [10][15]. The stated concern was other attackers reproducing the technique while potentially thousands of customers were still exposed [16].

The precedent PaperCut is working from is its own. "One of the biggest lessons from that incident was that the first attacker is not necessarily the biggest part of the problem," Chris wrote of 2023 [11]. In that round, once enough information about the n-day vulnerability became public, additional hacker groups moved in, including state-sponsored actors, and began exploiting exposed servers at scale [12].

What the account does not carry is the detail an administrator needs to scope the problem: no CVE identifier, no affected version numbers, no attacker attribution, and no count of compromised servers beyond the two customers who reported [19]. "This is not the full technical account. The incident is still active, we are still investigating and hardening, and there may be further updates," Chris wrote [13]. The company says it will publish a technical retrospective once the incident settles, as it did after 2023 [14].

What to watch

  • The promised technical retrospective, which should carry the exploit chain, affected versions and a CVE identifier.
  • Whether internet-wide scanning counts show the exposed PaperCut Application Server population falling after the removal request.
  • Whether a second wave appears from other groups once details of the chain circulate, as PaperCut says happened in 2023.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories