PaperCut Zero-Day Exploited: All NG and MF Versions at Risk
PaperCut has issued an urgent warning to customers after confirming that threat actors are actively exploiting a previously unknown vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. The vendor has released emergency patches for v25 and v26 and is treating the matter with the highest priority as investigations into active intrusions continue. Specific details about the flaw, exploitation method, and threat actor attribution remain undisclosed as of writing.
Administrators are urged to review their PaperCut Application Server environments for several indicators of compromise. These include intrusion-detection or endpoint-security alerts involving suspicious post-exploitation activity from "pc-app.exe," missing or truncated "server.log" files, and the presence of suspicious log entries such as "ERROR No suitable driver found for jdbc:no:x" and "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST." PaperCut strongly recommends that organizations immediately restrict internet-facing PaperCut servers to trusted IP addresses using firewall rules or network access controls, even if no suspicious activity has been observed. Security teams can use a port scanner to verify whether PaperCut Application Servers are inadvertently exposed to the public internet, and a WHOIS lookup to confirm ownership of any suspicious inbound connections.
This is not the first time PaperCut has been targeted. In 2023, a critical remote code execution flaw tracked as CVE-2023-27350 (CVSS 9.8) was weaponized by Russian threat actors and the financially motivated group Lace Tempest to deploy Cl0p and LockBit ransomware across enterprise environments. Given that print management servers typically hold broad Active Directory credentials and serve as gateways into corporate networks, defenders should treat any unpatched PaperCut instance as a critical risk. Administrators should also conduct a privacy checkup across connected endpoints and audit credentials that may have traversed the compromised server, rotating any privileged accounts immediately.
PaperCut has not yet released a CVE identifier for this latest vulnerability, and the article is developing. Organizations running PaperCut NG or MF should apply the emergency patches without delay, restrict external access, and hunt for the published IOCs across logs and EDR telemetry. As always, defending exposed management interfaces remains one of the most effective controls against opportunistic zero-day exploitation.