CuraSec

Act active

PaperCut second emergency patch after initial fix bypassed in wild

2026-08-28 21:21 UTC · BleepingComputer · read the source ↗ #papercut#active-exploitation#patch-bypass
  • Engineer — Act: PaperCut NG and MF are actively exploited and the first fix was bypassed, meaning unpatched and initially-patched instances remain at risk; update to the latest emergency release immediately and verify the new version is applied end-to-end.
  • SOC/IR — Plan: Active exploitation with a bypassed patch means print servers in the estate may already be compromised; build or tune detections for anomalous outbound connections and process spawning from PaperCut service accounts, and sweep logs back to the original disclosure date.
  • Leader — Plan: If PaperCut is in the environment, confirm with engineering that the second emergency patch is deployed and request a status update — active exploitation plus a failed first fix is the kind of event that can escalate to a breach if patching is delayed.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.