PaperCut Faces Active Exploitation of Zero-Day Vulnerability in Print Management Software
PaperCut is urging customers to apply an emergency patch or take servers offline following active exploitation of a zero-day vulnerability in its NG and MF print management products.

PaperCut, a widely used provider of print management software, is currently responding to a critical zero-day vulnerability that is being actively exploited in the wild. The flaw affects both PaperCut NG and PaperCut MF products, which are designed to manage access to printers, track usage, and facilitate printing from various devices within an organization.
The vulnerability came to light after a university's security team reported an attack targeting their PaperCut deployment. Following this report, PaperCut's security team investigated and confirmed the existence of the flaw, subsequently issuing an urgent security advisory. While the advisory itself does not detail the specific nature of the vulnerability, indicators of compromise suggest that the issue involves the software's web interface, potentially allowing attackers to gain deeper access into customer networks.
Evidence of exploitation includes alterations to log files and alerts generated by various security tools, such as intrusion detection systems, endpoint security solutions, and network monitoring packages. This suggests that attackers are leveraging the vulnerability to establish a foothold and potentially move laterally within compromised environments. The exact attack vector and the full extent of the potential network access remain under investigation.
In response to the active exploitation, PaperCut has developed and released an emergency patch. However, the company notes that this patch has not undergone its standard release process due to the urgency of the situation. This means customers applying the patch should do so with caution, understanding it is an interim solution.
PaperCut's advisory strongly recommends that customers take immediate action to mitigate the risk. The primary recommendation is to restrict access to the PaperCut web interface, allowing connections only from trusted internal IP addresses. For organizations unable to implement these network restrictions or those with public-facing PaperCut servers, taking the affected servers offline entirely is advised as a more secure, albeit disruptive, temporary measure.
The company is working diligently to develop a more robust and officially released fix for the vulnerability. Further updates will be provided to customers as soon as a stable, validated patch is ready for deployment. Until then, customers are advised to prioritize the immediate application of the emergency patch or the isolation of their PaperCut servers.
This incident highlights the persistent threat posed by zero-day vulnerabilities, especially those affecting software with broad network access capabilities like print management systems. The rapid exploitation underscores the importance of timely vendor responses and proactive customer security measures, including network segmentation and strict access controls for exposed services.