Skip to content

Security1 publisher3 min readPublished

Attackers bypassed PaperCut's first emergency patch on the day it shipped

PaperCut told NG and MF customers on August 27 that servers were already being exploited, with no CVE and no fix available. A patch that held arrived on September 1, and Picus Security says that gap is now the normal shape of a zero-day.

The Watch · Security desk

Illustration accompanying Attackers bypassed PaperCut's first emergency patch on the day it shipped

What happened

  • PaperCut's urgent advisory on August 27 told NG and MF customers that attackers were already exploiting their servers, at a point when no CVE had been assigned, no exploit was public and no patch existed.
  • A third patch landed on September 1, and Picus Security counts six days in which customers had neither a fix that held nor an exploit sample to test their own defences against.
  • Picus security research engineer Sila Ozeren Hacioglu, who wrote the account, puts last year's average gap between disclosure and exploitation at 21.5 days and says it is now measured in hours.
  • The hour-by-hour response walkthrough that follows the PaperCut timeline runs on an invented vulnerability, CVE-2026-1001, which the author states plainly is made up.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint An exposure check that depends on firing the real exploit cannot run when no exploit exists, so the validation step most teams rely on was unavailable for the whole PaperCut window.
  • decision With no patch, the only certain fix was taking a production print service offline, so the call moves down to the control layer: NGFW, WAF, endpoint policy, EDR and SIEM.
  • exposure Waiting for a public proof-of-concept before acting leaves an organisation exposed for the entire pre-PoC period, and Picus argues the first working exploit a defender sees may be the one used against them.
  • contradiction The failed-control findings that carry the mitigation-first case belong to a fictional CVE, so the only verifiable evidence in the piece is the PaperCut date sequence itself.

The August 27 advisory left PaperCut administrators without either input a response process runs on [1]. With no patch, there was nothing to remediate with. No public proof-of-concept meant no way to test whether the affected servers were reachable in their own environment [10]. A team whose exposure check is to fire the real exploit at the affected assets and watch what falls had nothing to fire for six days [4].

Sila Ozeren Hacioglu, a security research engineer at Picus Security, argues the exploit is the wrong unit of testing [5]. An exploit is a chain: delivery, execution, privilege escalation, process injection, credential access. Each step is a known technique, and techniques can be run against live controls before anyone has written the payload [11]. The workflow she describes maps the vulnerability to the techniques it would have to execute and runs those per asset against the NGFW, WAF, endpoint hardening, EDR and SIEM, producing a verdict on whether the chain would complete [12].

The hour-by-hour results are invented, and she says so. "The CVE is made up. The day is not: it is what PaperCut's customers lived through in August," Hacioglu wrote [9]. In that fictional run the NGFW missed delivery, the WAF detected the step without blocking it, endpoint hardening flagged execution, and neither the EDR nor the SIEM alerted [13]. The account includes no control results from any real PaperCut customer.

Hacioglu puts last year's average disclosure-to-exploitation interval at 21.5 days and says it is now measured in hours [6], without naming the dataset behind either figure [21]. "PaperCut isn't the outlier. It's the template," she wrote [7]. PaperCut's own sequence ran the other way round: exploitation was underway when the advisory published, which puts the disclosure-to-exploitation interval at zero or less for this vulnerability, not 21.5 days and not hours [20].

The dates are the checkable part of the argument. Advisory on August 27, first emergency patch on August 28, bypassed the same day, third patch on September 1 [1][18][2][3]. That is five days apart on the calendar, six if you count both endpoints as the customers had to [19].

In the walkthrough the patch ticket still gets opened for every affected asset on day one and parked until a patch exists; what actually deploys is a detection rule for the NGFW, a prevention rule for the WAF, GPO hardening for the endpoints, an IOA rule for the EDR and a detection rule for the SIEM [14]. Two of those five push automatically, the EDR and SIEM rules; the other three go out as tickets [22]. The re-run at 08:45 returns detected, blocked, blocked, alerted, alerted [15]. The article closes by promoting Picus's own event, The Validation Summit '26 [17].

What to watch

  • A CVE identifier or a KEV listing for the August PaperCut exploitation would date it independently of the vendor's own advisory.
  • Control-layer results from real PaperCut customers during August 27 to September 1. The Picus account has none.
  • A cited dataset behind the claim that disclosure-to-exploitation has fallen from 21.5 days to hours.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories