PaperCut warns of NG, MF flaw exploited in zero-day attacks

Cybersecurity firm PaperCut has issued a high-priority warning about a critical vulnerability in its widely-used print management software, which is being actively exploited by hackers in zero-day attacks. The company’s security team has confirmed that malicious actors are targeting all versions of PaperCut NG and MF, leaving organizations vulnerable to data breaches and system compromise.

The vulnerability affects not only the latest versions but also all previous ones, making it a pressing concern for companies with Internet-exposed PaperCut Application Servers. To mitigate this risk, PaperCut is urging administrators to restrict access to the web interfaces of these servers by using firewall rules or network access controls to limit connections from trusted IP addresses.

The company has released emergency patches for customers who have public-facing PaperCut NG/MF servers and are unable to take other mitigating action. However, even with these patches in place, it’s essential for administrators to remain vigilant and monitor their systems closely for signs of compromise. Indicators of suspicious activity may include unusual behavior from the legitimate PaperCut process (pc-app.exe) or modifications to server.log files.

What makes this situation particularly concerning is that hackers are not just exploiting the vulnerability but also using it as a springboard to gain access to company networks. This can lead to further attacks, data theft, and system compromise, putting sensitive information at risk. As PaperCut continues its investigation, it will provide updates on additional indicators of compromise and remediation guidance.

This is not an isolated incident; PaperCut has been targeted by threat actors in the past after security vulnerabilities were disclosed. In 2023, attackers began exploiting a critical vulnerability (CVE-2023-27350) that allowed unauthenticated access to vulnerable servers. Microsoft later linked some of these attacks to the Clop ransomware operation and observed intrusions leading to LockBit ransomware attacks.

The exploitation of PaperCut vulnerabilities has spread to other threat actors, including Iranian state-backed hacking groups and the Bl00dy Ransomware Gang. These incidents highlight the importance of staying vigilant and regularly updating software to prevent zero-day exploits.

As a precautionary measure, administrators should review their network configurations and ensure that all Internet-facing servers are properly secured. By taking proactive steps to secure their systems, organizations can reduce the risk of being targeted by these attacks. PaperCut’s emergency patches are an essential first step, but ongoing monitoring and vigilance are crucial in preventing further compromise.

In conclusion, this zero-day attack serves as a stark reminder of the importance of robust cybersecurity measures in today’s threat landscape. By staying informed and taking proactive steps to secure their systems, organizations can minimize the risk of being targeted by these attacks.


Source: Bleeping Computer — 2026-08-27