← Blog · · df00tech

PaperCut Discloses Zero-Day Exploitation of NG/MF Print Management Software

security-news advisory

PaperCut has issued an advisory warning that a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software is being actively exploited in zero-day attacks, according to a report from BleepingComputer. Details on the specific flaw, its CVE identifier, and technical root cause have not yet been published by PaperCut or covered in the source reporting.

Why It Matters

PaperCut NG and MF are widely deployed print management platforms used across enterprise, education, and government environments. PaperCut software has a documented history of being a high-value target — prior vulnerabilities in the product line have been exploited by ransomware affiliates and other threat actors to gain initial access and pivot into broader networks. Any organization running PaperCut NG or MF, regardless of version, should treat this as a currently active threat rather than a theoretical risk, since exploitation is already reported to be underway.

What Defenders Should Do Now

  • Check PaperCut's official advisory and security bulletins directly for patch availability, affected version ranges, and any interim mitigations, since specifics were not detailed in initial press coverage.
  • Restrict external and untrusted network access to PaperCut application servers where possible, particularly the admin web interface, until a patch is confirmed and applied.
  • Review PaperCut server logs for anomalous authentication attempts, unexpected admin console access, unusual process spawning from the PaperCut service account, or outbound connections initiated by the PaperCut server process.
  • Hunt for indicators consistent with post-exploitation activity following print-server compromise, such as new scheduled tasks, service creation, or credential access attempts originating from hosts running PaperCut.
  • Ensure PaperCut servers are included in asset inventories and vulnerability scanning scope so that a patch can be tracked and applied promptly once released.

This is a developing story and technical details remain limited at time of writing. Defenders should monitor PaperCut's official channels for the forthcoming patch and IOC guidance. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.