VMTech
Discuss a project

PaperCut Issues Emergency Patch for Actively Exploited Zero-Day

PaperCut Issues Emergency Patch for Actively Exploited Zero-Day

PaperCut confirms active exploitation

PaperCut has warned that attackers are actively exploiting a zero-day vulnerability affecting every version of its PaperCut NG and PaperCut MF print-management software. The company said it has confirmed customer incidents and is treating the matter as a high-priority security event.

An emergency patch is available for PaperCut NG and MF versions 25 and 26. PaperCut’s investigation remains ongoing, and it has not disclosed technical details of the vulnerability, the exploitation method, or the actors responsible for the attacks.

Immediate exposure reduction is advised

Organizations running a PaperCut NG/MF Application Server exposed to the internet should immediately restrict access to trusted IP addresses. PaperCut recommends firewall rules, network access controls, or equivalent measures to ensure its server web interfaces cannot be reached from untrusted internet addresses.

The vendor said this restriction should be applied even where administrators have not yet observed suspicious activity. That guidance places particular importance on identifying systems that may have been published externally for administration, printing workflows, or remote access.

Indicators for security teams

PaperCut has released a limited set of indicators of compromise for investigation. Security teams should review alerts from intrusion-detection, endpoint-security, and network-monitoring products involving the PaperCut Application Server, especially suspicious post-exploitation activity originating from pc-app.exe.

Administrators should also look for PaperCut server.log files that are missing, unexpectedly truncated, or deleted. The vendor identified two log entries that may be relevant: ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.

Why the warning warrants prompt action

PaperCut products have drawn attacker interest before. In 2023, a critical vulnerability in PaperCut MF and NG, CVE-2023-27350 with a CVSS score of 9.8, was exploited by Russian threat actors and the financially motivated group Lace Tempest to deliver Cl0p and LockBit ransomware.

The current issue has no public vulnerability identifier or exploitation details yet, so defenders cannot rely on signatures alone to assess their position. The practical business implication is to patch supported version 25 and 26 deployments, remove untrusted internet access, and investigate the listed process and log indicators across all PaperCut Application Servers.

#cybersecurity#zeroday#papercut#vulnerability
Open analytics
On the site 0 views
min read 3 28.08.2026
Instagram

PaperCut Issues Emergency Patch for Actively Exploited Zero-Day

Open the post on Instagram ↗