CVE-2023-27350: PaperCut MF/NG Improper Access Control Vulnerability.
PaperCut MF/NG Improper Access Control Vulnerability. PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.
- CISA KEV-listed (remediation due 2023-05-12)
- used in ransomware campaigns
- EPSS 100.0% (100.0% percentile)
- CVSS 9.8 critical
Related briefings
- Hackers exploit PaperCut zero-day to take over servers 2026-08-28
- Microsoft Exposes Onyx Sleet's Expanding Malware Arsenal Targeting Aerospace and Defense Organizations 2026-02-16
Linked threat actors
- Andariel machine-inferred link
- Medusa Ransomware
- Buhti machine-inferred link