New research explains how PaperCut print-server fixes were bypassed
Research published: 9 October 2026
Original attacks and fixes: 27 August to 10 September 2026
Researchers at watchTowr have published a detailed account of flaws in PaperCut NG and MF, software that manages printing for schools, offices and other organisations. PaperCut warned of active attacks on 27 August. The new 9 October research explains how an authentication weakness could be combined with a code-execution weakness, and how researchers found ways around early emergency fixes.
An *authentication bypass* lets a person reach functions that should require a login. Paired with a second flaw, it could let someone run commands on the print-management server. That server may be connected to other business systems, so the concern extends beyond interrupted printing. PaperCut says it has confirmed customer incidents, but watchTowr’s newly published patch-bypass analysis does not mean every patched customer was attacked.
The dates and versions matter. watchTowr describes weaknesses in the original 26.0.3 release and in subsequent emergency builds. PaperCut says its fully tested maintenance releases 26.0.5, 25.0.13 and 24.1.10 contain the relevant fixes and replace the emergency patches. It advises all NG and MF customers to upgrade, even if their server is not publicly reachable. PaperCut says Mobility Print and Print Deploy server components are not affected by these issues.
An organisation using PaperCut should confirm its installed build, move from an early emergency patch to the appropriate maintenance release, and check the vendor’s published signs of compromise. If a print supplier runs the server, ask it to confirm both the update and the incident review.








Comments