Critical Vulnerability Exploited in PaperCut Software Leaves Thousands Exposed
A severe zero-day vulnerability in PaperCut’s print management solutions has been exploited in the wild, prompting an emergency patch release from the company. The flaw, which affects PaperCut NG and MF versions, allows attackers to gain unauthorized access to the application server, potentially leading to data breaches and other malicious activities.
The vulnerability has yet to be assigned a Common Vulnerabilities and Exposures (CVE) identifier, and no technical details have been shared by PaperCut. However, the company is urging its customers to install the emergency patches as soon as possible and take additional security measures to protect their systems. This includes disconnecting the application server from the internet and restricting access to trusted IP addresses.
The exploitation of this vulnerability has already resulted in confirmed customer incidents, with PaperCut treating the matter with the highest priority. The company’s investigation is ongoing, but it’s unclear who is behind the attacks or what their motivations may be. Indicators of compromise (IoCs) suggest that attackers are delivering malware or other post-exploitation tools through a suspicious file named “pc-app.exe”.
PaperCut has also noted that unexpectedly truncated or deleted server.log files could indicate an intrusion, as attackers often attempt to cover their tracks by modifying log files. This is not the first vulnerability in PaperCut NG/MF to be exploited in the wild; CISA’s Known Exploited Vulnerabilities catalog includes three previously identified flaws.
The impact of this vulnerability extends beyond individual organizations, with approximately 1,000 PaperCut instances currently exposed to the internet. A majority of these systems are located in North America and Europe, according to data from the ShadowServer Foundation. This highlights the importance of prioritizing security measures for organizations using print management solutions.
To mitigate this risk, we recommend that all PaperCut customers take immediate action by installing the emergency patches and following the additional security guidelines provided by the company. Regularly monitoring system logs and implementing robust access controls can also help prevent unauthorized access to sensitive data. By taking proactive steps to secure their systems, organizations can minimize the risk of a successful attack and protect their users’ information.
Source: SecurityWeek — 2026-08-28