Dim NYC office corner with a leftover multifunction copier and a small tower PC by a window overlooking water towers at dusk.

That PaperCut Box Next to the Copier Still Answers From the Street

Microsoft 365 does not patch the print server.

Yesterday’s leftover problem was the SQL box under the desk that hit CISA’s exploited list. Today’s leftover problem is different: a PaperCut NG or PaperCut MF Application Server sitting next to a multifunction copier in a Class-B suite — Staten Island law, Bay Ridge medical, outer-borough accounting — still answering on the web UI from places it should never answer from. The firm moved mail and files to the cloud. The print queue stayed on a mini-tower or a VM that “just runs PaperCut.” Admins on r/sysadmin have been comparing notes about exposed print servers under active attack. That thread is the mood, not a statistic.

This is not a CISA Known Exploited Vulnerabilities item as of our August 30, 2026 catalog check. Yesterday’s SQL CVE is on KEV. These PaperCut CVEs are not (yet). That does not make them optional. PaperCut’s own bulletin says the company is investigating active exploitation, is aware of confirmed customer incidents, and shipped two emergency patches in one day because the first one was not enough. A university customer helped the vendor and researchers reproduce the issue. That is confirmed abuse somewhere in the customer base. It is not a claim that a named NYC firm was hit, and we are not inventing borough infection counts.

What PaperCut actually said

PaperCut’s urgent security advisory (last updated August 30, 2026 on the page we opened) is the primary source. Immediate action, before you argue about version strings: if the Application Server is accessible from the public internet, restrict web access to trusted IP addresses only. Do that even if you have not seen suspicious activity.

Two CVEs sit under that bulletin. Do not mash them into one slogan.

CVE-2026-81578 — Authentication Bypass (CWE-306). Unauthenticated remote requests aimed at admin functions can trigger backend actions before access validation finishes. That lets an unauthenticated remote attacker modify certain system configurations. PaperCut rates it CVSS 4.0 8.8 HIGH (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N). Mitigated in Emergency Patch Release 2.

CVE-2026-82078 — Unsafe Dynamic Class Loading in the Database Connector (CWE-470). The product can instantiate database driver classes from configurable driver names without an allowlist. If an attacker can manipulate system configuration parameters, that path can run arbitrary Java bytecode on the classpath under the PaperCut server process. PaperCut rates it CVSS 4.0 9.4 CRITICAL (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Also mitigated in Release 2.

NVD published both records on August 28, 2026 (last modified August 29). Descriptions match the vendor. NVD 3.x scores were still N/A when we checked. NVD’s affected floors for PaperCut MF/NG are versions below 24.1.10, 25.0.13, and 26.0.5 — those three builds are the patched floors you confirm after install.

The advisory applies to all versions of PaperCut NG and PaperCut MF. Print Deploy and Mobility Print are not affected. Site Servers and secondary/print servers still need a patched build, not only the primary Application Server. For v23 and earlier, PaperCut’s recommended path is upgrade to the latest version; there is no emergency patch train for those older lines.

Rapid7’s August 28 analysis (timeline and context only) notes that a university customer’s DFIR work helped reproduction, that the first patch could be bypassed, and that PaperCut’s 2023 CVE-2023-27350 was broadly exploited, including by ransomware operators. That 2023 history is why leftover print infrastructure gets weekend attention. We are not copying Rapid7’s request paths or any chain details into this post.

Why the first emergency patch is not the finish line

PaperCut shipped the first emergency patch for v25/v26 at 28 Aug 2026 02:10am AEST. After further work with Huntress and watchTowr, Emergency Patch Release 2 landed at 28 Aug 2026 8:42pm AEST for those trains, and v24 Release 2 at 28 Aug 10:08pm AEST. PaperCut’s instruction is blunt: install Release 2 even if you already applied the original emergency patch.

These builds are not an official release. They did not go through the usual release process. They are emergency patches aimed at public-facing servers that cannot otherwise mitigate. As of 30 Aug 2026 10:34am AEST, PaperCut engineering was still working toward an official release. Until that lands, Release 2 plus internet restriction is the line to hold. If you applied Friday morning’s first patch and stopped, you are not done.

Internet exposure is the urgent control

Before the upgrade conversation finishes, shrink who can reach the web UI. PaperCut’s own first action is: Application Server reachable from the public internet → restrict to trusted IPs now.

In a 15-user NYC suite the failure mode is ordinary. Someone forwarded ports 9191 or 9192 years ago so a partner could release a job from home. A firewall rule stayed after a VPN project. The copier VLAN is flat with the guest Wi-Fi. The Application Server answers from the street while the MFP itself only talks inside the building. Microsoft 365 license status will not tell you any of that. Restrict first. Patch second. Inventory site and secondary servers third.

Print jobs are SHIELD data

Print jobs carry names, matter captions, account numbers, EOBs, and draft pleadings. Under New York’s SHIELD Act, a business that owns or licenses computerized private information of a New York resident has to maintain reasonable safeguards. Regularly testing key controls sits on the statute’s technical-safeguard list. An internet-reachable PaperCut Application Server on an unpatched train is not a tested control.

We are not inventing a SHIELD enforcement action off these CVEs. The SHIELD checklist for NYC SMBs is the statute walk. This post is the print host. Tenant retention in Microsoft 365 is also not a backup of that Application Server — we already covered what a tenant-wide event takes from a law or accounting firm. Cloud mail does not restore server.log or the print database.

Leftover on-prem boxes are a pattern here. We already wrote about the closet Exchange server and yesterday’s SQL KEV instance. PaperCut is the print version of the same habit: the cloud cutover left one machine that “just works” next to the MFP.

Eight things a 15-user tenant can finish this weekend

  1. 1. Name the product and the version from About. Is it PaperCut NG or PaperCut MF? Open the Application Server admin UI and write down the exact version string — v24, v25, v26, or older. If nobody can find About, that is the finding.
  1. 2. Ask whether the web UI answers from the public internet. From a phone off the office Wi-Fi, try the hostname or public IP used for remote print release — commonly ports 9191 / 9192, or whatever URL staff bookmarked. If it loads from the street, stop and restrict. PaperCut’s bulletin puts that restriction ahead of “we will patch Monday.”
  1. 3. Restrict web access to trusted IPs immediately. Firewall or reverse-proxy allowlist: office static IPs, VPN egress, and the jump host your MSP uses. No temporary any/any until the upgrade finishes. If the UI was public for one partner’s convenience, give them VPN instead of a bare Application Server on the internet.
  1. 4. Install Emergency Patch Release 2 — not the first emergency build. Pull Release 2 from PaperCut’s advisory for your train. Install it even if the first emergency patch is already on the box. After install, confirm you are at least 24.1.10, 25.0.13, or 26.0.5 (NVD’s patched floors). Screenshot About before and after. On v23 or earlier, plan the upgrade to a current train; there is no Release 2 for those lines.
  1. 5. Update Site Servers and secondary/print servers, not only the primary. PaperCut’s bulletin is explicit. Print Deploy and Mobility Print are out of scope for these CVEs — do not use that as an excuse to skip the Application Server and site servers.
  1. 6. Card/ID lookup and SAML customers: read the post-patch notes. Default card-number lookup is off. If you need it, PaperCut documents adding security.card-number-lookup.enabled=Y to server/security.properties and restarting. Post-patch, some sites reported external DB Card/ID lookup and SAML not behaving as expected — PaperCut was investigating as of the August 30 update. For SQL Server card lookups still on the legacy SourceForge jTDS driver, move to the latest supported Microsoft SQL JDBC driver per the bulletin.
  1. 7. Look for the vendor’s defensive indicators — without a hunt cookbook. PaperCut lists things to look for, not recipes to produce: alerts tied to the PaperCut Application Server or suspicious post-exploitation activity from pc-app.exe; missing, truncated, or deleted server.log; log lines such as ERROR No suitable driver found for jdbc:no:x, ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST, and (updated 30 Aug 2026 3:35pm AEST) a Derby memory URL shaped like jdbc:derby:memory:pwn;create=true or cardID errors containing VALUES CAST(X'cafebabe; unexpected short-named .class files under server\lib\ and .cmd/.out under server\data\content\ (may already be cleaned up); pc-app.exe launching cmd.exe for whoami and ver; an unexpected Windows service named “Remote Access Service” running SimpleService.exe from under C:\ProgramData\JWrapper-Remote Access\; unexpected AnyDesk. Absence of these indicators is not proof the host is clean.
  1. 8. If compromise is suspected: secure backups, wipe, rebuild. PaperCut’s guidance: secure current backups, completely wipe and rebuild the Application Server, restore a clean backup taken before suspicious behavior, and activate your organization’s security response. Do not “clean” a suspect print server in place and call it done. Confirm the backup you will restore is not the only copy sitting on the same tower next to the MFP.

Identity and mail filtering still decide how someone gets a foothold in the tenant. This post is whether the leftover print Application Server is still reachable from the street on a build before Release 2.

What we will put in writing

We will not hand you a generic “patch your print stack” slide.

We will tell you, in writing:

  • Which host is the PaperCut NG or MF Application Server, and the exact version string from About
  • Whether that host’s web UI is reachable from the public internet (and on which ports), and whether trusted-IP restriction is in place
  • Whether Emergency Patch Release 2 is installed and whether the build meets 24.1.10 / 25.0.13 / 26.0.5
  • Whether Site Servers and secondary/print servers are on patched builds, not only the primary
  • Whether logs, services, or the vendor IOC list above look off enough to justify a wipe-and-rebuild instead of an in-place patch
  • Whether the only backup of that Application Server is the same machine next to the copier

If you are on v23 or earlier, we will put the upgrade date on a calendar you can see — not a “we’ll revisit next quarter” note.

Call this weekend, not after the official release lands

Call MicroSky at (718) 672-2177 or visit microskyms.com for a free, no-obligation look at that leftover PaperCut Application Server. We serve NYC, Staten Island, New Jersey, and the tri-state.

Ask whether the web UI answers from the street, whether Release 2 is actually installed, and where the last clean backup of that print server lives.

Share This Article