← Blog · · df00tech

PaperCut Ships Second Emergency Patch After Initial Fix for Exploited Bugs Falls Short

security-news advisory

What happened

PaperCut has issued a second emergency security update for two vulnerabilities in its PaperCut NG and MF print management software that are being actively exploited, according to BleepingComputer. The vendor's original fix was found to have multiple bypasses by researchers, prompting this follow-up release. Specific technical details of the bypass techniques were not disclosed in the report.

Why it matters for defenders

PaperCut is widely deployed print management software in enterprise and education environments, and it has a history of being targeted in real-world intrusions. Because the flaws are described as actively exploited and the first round of patching was incomplete, organizations that applied only the initial fix should not assume they are protected — the exposure window may still be open.

What defenders should watch for or do now

  • Confirm which PaperCut NG/MF version is actually running and verify it includes this second emergency patch, not just the first one.
  • Review PaperCut's own advisory for the specific CVE identifiers, affected version ranges, and any indicators of compromise once published.
  • Monitor PaperCut application and server logs for anomalous administrative actions, unexpected script execution, or new user/printer configuration changes originating from the PaperCut service account.
  • Watch for unusual outbound network connections or process spawning from the PaperCut application server, consistent with post-exploitation activity seen in prior PaperCut incidents.
  • Where patching cannot happen immediately, consider restricting network access to the PaperCut admin interface to trusted management networks only.

Developing story

This is based on early reporting and details may evolve as PaperCut and researchers publish more information, including formal CVE assignments and technical bypass analysis. For the latest, see the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.