A critical zero-day vulnerability affecting all versions of PaperCut NG and PaperCut MF print management software is currently being actively exploited by malicious actors, prompting an urgent warning from PaperCut to its global customer base. The company has swiftly released emergency patches for versions v25 and v26 to mitigate the threat, emphasizing the highest priority being placed on this incident.
Immediate Action Required: Patch and Restrict Access
PaperCut has confirmed “customer incidents” and has launched an ongoing investigation into the nature and scope of the attacks. While specific details about the flaw, its exploitation methods, or the perpetrators remain undisclosed, the urgency of the situation cannot be overstated. Users are strongly advised to take immediate protective measures.
Indicators of Compromise (IoCs) to Watch For:
- Suspicious post-exploitation activity originating from “pc-app.exe” detected by intrusion-detection, endpoint-security, or network-monitoring tools on the PaperCut Application Server.
- Missing, unexpectedly truncated, or deleted
PaperCut server.logfiles. - The presence of specific error entries within
server.log, such as:ERROR No suitable driver found for jdbc:no:xERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
Protecting Your PaperCut Servers
For organizations with PaperCut NG/MF Application Servers exposed to the internet, the most critical immediate step is to restrict access to trusted IP addresses only. PaperCut explicitly states: “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.” This action is crucial even if no suspicious activity has been observed yet.
This isn’t the first time PaperCut has faced such a severe threat. In 2023, a critical flaw (CVE-2023-27350, CVSS score: 9.8) in PaperCut MF and NG was leveraged by Russian state-sponsored threat actors and the financially motivated Lace Tempest hacking group to deploy notorious ransomware strains like Cl0p and LockBit. The current zero-day exploitation underscores the persistent and evolving threat landscape targeting critical infrastructure software.
This is a developing story, and users are encouraged to monitor official PaperCut communications for further updates and guidance.
For more details, visit our website.
Source: Link


Leave a comment