PaperCut Zero‑Day Under Active Attack Puts Print Servers at the Center of Corporate Cyber Risk
A newly disclosed zero‑day flaw in PaperCut NG and MF print management software is being actively exploited, with confirmed customer incidents and emergency patches only available for the latest versions.
A critical, previously unknown vulnerability in PaperCut’s popular print management software is being actively exploited, exposing a wide range of organizations to potential network compromise.
On 28 August, security researchers reported that a zero‑day flaw affecting all versions of PaperCut NG and MF has been used in real‑world attacks, with confirmed incidents among customers. PaperCut said emergency patches are available for versions 25 and 26 of the software, but the company has not publicly detailed the exploit method or identified who is behind the intrusions.
PaperCut NG and MF are widely deployed across schools, universities, businesses and public‑sector institutions to manage printing, scanning and user quotas. Because the software typically sits on servers that interact with directory services and user credentials, a compromise can offer attackers a foothold inside an organization’s network rather than at its perimeter.
For IT teams, the immediate concern is that attackers may already be moving from vulnerable PaperCut servers into more sensitive systems, harvesting credentials or installing additional backdoors. The lack of public technical detail about the exploit chain makes it harder for defenders to build custom detections beyond the vendor’s own guidance and logs.
From an operational standpoint, print management is deeply embedded in everyday workflows. Disabling or isolating PaperCut servers to protect networks can disrupt routine tasks across campuses and offices, forcing administrators to balance service continuity against the risk of a wider breach.
Strategically, the incident shows how attackers are targeting widely deployed infrastructure tools that have broad reach but often receive less security attention than headline applications.
Key signals to watch now are additional technical advisories from PaperCut and major cybersecurity firms, indicators of compromise that can help organizations hunt for intrusions, and any attribution pointing to a particular threat group.
Sources
- OSINT