PaperCut NG and MF Zero-Day Vulnerabilities Exploited in Active Attacks
PaperCut has warned that threat actors are actively exploiting zero-day vulnerabilities in all versions of its PaperCut NG and PaperCut MF print management software.
The company confirmed attacks against customers and urged organizations with PaperCut application servers exposed to the internet to immediately restrict access to the web interface using firewall rules or network access controls.
“The PaperCut Software Security Response Team is investigating active exploitation of vulnerabilities affecting PaperCut NG and PaperCut MF,” the company said in an urgent security advisory published Thursday.
“We are aware of the confirmed customer incident and are treating this matter as a top priority,” PaperCut added.
The company said the security flaw affects all versions of PaperCut NG and PaperCut MF. However, PaperCut has not yet disclosed technical details about the vulnerability or explained how attackers are exploiting it.
PaperCut’s security team reportedly reproduced the vulnerability using information provided by a university customer.
PaperCut releases emergency security patch
PaperCut has released an emergency patch for organizations operating publicly accessible PaperCut NG or PaperCut MF application servers.
“This is an emergency patch for customers using public PaperCut NG/MF servers and are unable to take other mitigation steps,” the company said in its advisory.
Administrators should apply the emergency update as soon as possible. Organizations that cannot immediately patch their servers should use firewall rules, VPN access, or other network access controls to limit the PaperCut web interface to trusted IP addresses only.
PaperCut shares indicators of compromise
PaperCut has also published indicators of compromise that administrators can use to check whether their servers may have been breached.
Potential warning signs include suspicious activity involving the legitimate PaperCut pc-app.exe process. Administrators should also check whether server.log files have been modified, deleted, or are missing.
Security teams should look for the following errors in the server log:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
PaperCut cautioned that the absence of these indicators does not confirm that a server is secure or rule out a compromise.
The company has not disclosed who is behind the attacks, what threat actors are doing after compromising PaperCut servers, or whether customer data has been stolen.
PaperCut said it will continue updating its recommendations with additional indicators of compromise and remediation guidance as the investigation progresses.
BleepingComputer contacted PaperCut for additional information about the zero-day exploitation and will update this article if the company responds.
Previous PaperCut vulnerability exploited in ransomware attacks
PaperCut software has previously been targeted by multiple threat actors after critical security flaws were disclosed.
In April 2023, attackers began exploiting the critical CVE-2023-27350 vulnerability in PaperCut NG and MF. The flaw allowed unauthenticated attackers to bypass authentication and execute remote code on vulnerable servers.
Microsoft later linked some of the attacks to the Clop ransomware operation, which used vulnerable PaperCut servers to gain initial access to corporate networks. Microsoft also observed intrusions that resulted in LockBit ransomware attacks.
Although PaperCut includes a print archive feature that can store documents sent through its servers, Clop later told BleepingComputer that it used the vulnerability primarily to obtain initial access to victims’ networks rather than directly steal archived documents from PaperCut servers.
Other threat actors also adopted the exploit. Microsoft reported that Iranian state-sponsored hacking groups were exploiting CVE-2023-27350, while the FBI and CISA warned in May 2023 that the Bl00dy ransomware gang was targeting vulnerable PaperCut servers in attacks against the education sector.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




