PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut Warns of Zero-Day Attacks Exploiting NG, MF Flaw, Urges Immediate Action

A critical vulnerability in PaperCut’s print management software has been exploited in zero-day attacks, leaving organizations with Internet-exposed Application Servers vulnerable to compromise. The company behind the software, PaperCut, has issued an urgent security advisory warning customers of confirmed incidents and urging them to take immediate action to protect their systems.

The vulnerability affects all versions of PaperCut NG (Next Generation) and MF (Multi-Functional), a widely used print management solution for businesses and educational institutions. While the exact nature of the flaw remains unknown, PaperCut’s security team has reproduced it using information provided by a University customer, and emergency patches have been released to address the issue.

The attacks are particularly concerning because they can be carried out without requiring valid login credentials. This means that even if an organization has strong access controls in place, hackers may still be able to breach its systems through the vulnerable PaperCut software. The company warns that a lack of indicators of compromise does not necessarily mean that a server has not been compromised.

To mitigate this risk, PaperCut recommends restricting access to the web interfaces of Application Servers to trusted IP addresses using firewall rules or network access controls. Administrators should also be on the lookout for suspicious activity from the legitimate PaperCut process (pc-app.exe) and unusual modifications to server.log files. However, as PaperCut warns, the absence of indicators does not guarantee that a server is secure.

This vulnerability has significant implications for organizations that rely on PaperCut’s print management software. Given its widespread adoption in various industries, including education and finance, it’s essential for administrators to take immediate action to patch their systems and restrict access to trusted IP addresses. The attacks may be more widespread than initially thought, given the company’s history of being targeted by threat actors after security vulnerabilities were disclosed.

In a previous instance, attackers exploited a critical vulnerability in PaperCut (CVE-2023-27350) that allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers. Microsoft later linked these attacks to the Clop ransomware operation, which used the vulnerability for initial access to company networks. This raises concerns about the potential for data theft or other malicious activities in the current attacks.

While details about the attackers’ motivations or actions remain scarce, it’s clear that this vulnerability poses a significant threat to organizations using PaperCut’s print management software. To protect themselves from zero-day attacks, administrators should prioritize patching their systems and restricting access to trusted IP addresses. As always, vigilance is key in today’s cybersecurity landscape.

Practical takeaway: If you’re an administrator responsible for managing PaperCut Application Servers, take immediate action to restrict access to the web interfaces of your servers using firewall rules or network access controls. Ensure that all patches are applied, and monitor your systems closely for any suspicious activity related to the legitimate PaperCut process (pc-app.exe) or modifications to server.log files.


Source: Bleeping Computer — 2026-08-27