PaperCut: Zero-day exploit hits NG and MF print management servers
Vendor confirms active exploitation, releases emergency patch, and tells customers to restrict public-facing server access.

PaperCut has published an urgent security advisory after confirming that attackers are exploiting a previously unknown vulnerability in its PaperCut NG and PaperCut MF print management products. The vendor says it is aware of confirmed customer incidents and is treating the matter with the highest priority. The advisory was published Thursday, and PaperCut's security team reproduced the issue using information provided by a university customer.
Who is affected: Any organization running PaperCut NG or PaperCut MF with an internet-exposed Application Server is at risk, according to the vendor. The flaw affects all versions of both products.
What to do now: The company urges immediate restriction of web interface access to trusted IP addresses using firewall rules or network access controls. For deployments with public-facing servers that cannot apply such restrictions, PaperCut has released an emergency patch. The advisory does not describe a full update schedule beyond this emergency measure.
How to check for compromise: PaperCut shared several indicators. They include suspicious activity from the legitimate PaperCut pc-app.exe process and server.log files that have been modified, deleted, or are missing. Administrators should also look for additional error patterns in server.log, as described in the advisory. PaperCut warns that a lack of these indicators does not mean a server has not been compromised.
What is not yet known: PaperCut has not published technical details about the vulnerability or how it is being exploited. It has also not disclosed who is behind the current attacks, what actions attackers take after gaining access, or whether data is being stolen. The company says it will update the advisory as its investigation continues. BleepingComputer contacted PaperCut for further information.
Historical context, not current attribution: PaperCut has been targeted before. In April 2023, a critical authentication bypass and remote code execution flaw tracked as CVE-2023-27350 was exploited widely. Microsoft linked some of that activity to Clop and LockBit ransomware operations, and also observed Iranian state-backed groups using the flaw. CISA and the FBI later warned that the Bl00dy Ransomware Gang was targeting vulnerable PaperCut servers in the education sector. Clop later told BleepingComputer that it had used the earlier vulnerability for initial access rather than to steal archived documents directly from PaperCut servers. That earlier campaign is separate from the current advisory and should not be read as confirmation that the same groups are involved now.
Patched? PaperCut has released an emergency patch for customers with public-facing PaperCut NG/MF servers who are unable to take other mitigating action. The material reviewed does not include a CVE identifier or severity rating for the current flaw.