PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut has issued an emergency patch for a zero-day vulnerability actively exploited in its NG and MF print management software, affecting all versions. The company is investigating confirmed customer incidents and advises immediate access restriction for internet-expos…
Intelligence analysis by Gemini 2.5 Flash

A critical zero-day vulnerability in PaperCut's print management software, PaperCut NG and MF, is being actively exploited, prompting the company to release an emergency patch and warn customers. The attacks affect all versions, and an investigation is underway, with specific indicators of compromise shared to help organizations detect potential breaches.
Imagine a special printer program that helps big offices manage their printing. Someone found a secret trick (a "zero-day") to sneak into this program without anyone knowing, like a secret key that works on all the locks. The company that makes the program quickly made a new, stronger lock (a patch) and told everyone to put it on right away, especially if their printer program is connected to the internet, to stop the bad guys from getting in and causing trouble.
Analysis
PaperCut, a prominent provider of print management software, has issued an urgent alert regarding a zero-day vulnerability that is currently being actively exploited in the wild. This critical flaw impacts all versions of its PaperCut NG and PaperCut MF software, which are widely deployed in enterprise environments to manage printing operations. The company has acknowledged confirmed customer incidents and is treating the matter with the highest priority, underscoring the severe nature of the threat.
PaperCut NG/MF
The vulnerability specifically targets the PaperCut NG and PaperCut MF print management software, which are integral to many organizations' IT infrastructure. The company has responded by releasing an emergency patch for versions v25 and v26, urging customers to apply it immediately. This rapid response is crucial given the active exploitation, aiming to close the window of opportunity for attackers as quickly as possible. An ongoing investigation is in progress to fully understand the scope and nature of the attacks, as well as the underlying flaw.
Zero-Day Exploitation
The active exploitation of this zero-day vulnerability means that attackers are leveraging a previously unknown flaw before a patch was widely available, making it particularly dangerous. While specific details about the flaw, the method of exploitation, or the identity of the threat actors remain undisclosed, PaperCut has provided several indicators of compromise (IoCs). These include suspicious post-exploitation activity from "pc-app.exe" on the PaperCut Application Server, unexpected truncation or deletion of server.log files, and specific error entries within the server.log related to database lookups. These IoCs are vital for organizations to detect if their systems have already been compromised.
CVE-2023-27350
This is not the first time PaperCut software has been targeted by sophisticated threat actors. In 2023, a critical flaw identified as CVE-2023-27350, with a CVSS score of 9.8, was also actively exploited. That particular vulnerability was leveraged by Russian state-sponsored threat actors and a financially motivated hacking group known as Lace Tempest. These groups used the flaw to deliver notorious ransomware strains such as Cl0p and LockBit, highlighting the potential for severe financial and operational disruption. The recurrence of such high-impact vulnerabilities underscores the need for continuous vigilance and robust security practices for users of PaperCut's products.
Key points
- PaperCut has confirmed active exploitation of a zero-day vulnerability in its NG and MF print management software.
- An emergency patch has been released for versions v25 and v26, with an investigation into confirmed customer incidents ongoing.
- All versions of PaperCut NG and MF are affected by the vulnerability, requiring immediate attention.
- Customers with internet-exposed PaperCut Application Servers are advised to immediately restrict access using firewall rules or network controls.
- Previous critical flaws in PaperCut software, like CVE-2023-27350, have been exploited by ransomware groups such as Cl0p and LockBit.
The company's swift release of an emergency patch and immediate customer alerts demonstrate a proactive approach to mitigating the threat. This rapid response, coupled with clear guidance on restricting access, could significantly limit the scope and impact of the ongoing zero-day exploitation.
Despite the patch, the active exploitation of a zero-day vulnerability in widely deployed software poses a significant risk, especially for organizations that are slow to patch or have internet-exposed servers. The lack of details on the flaw or attackers suggests a sophisticated threat, potentially leading to widespread data breaches or ransomware infections before full remediation.



