Breaking
SecurityConfirmed

PaperCut Zero-Day Patch Urged

PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.

··2 hours ago·3 min read
Yellow and green cables are neatly connected
Photo by Albert Stoynov on Unsplash

The makers of the widely used PaperCut print management platform have rushed out emergency fixes after confirming that a previously unknown vulnerability is being actively exploited in the wild. The company is urging customers to apply the patch immediately and is also recommending that application servers be disconnected from the internet where possible.

Exploited Zero-Day, No CVE Yet

The flaw, which affects both PaperCut NG and PaperCut MF, has not yet been assigned a Common Vulnerabilities and Exposures (CVE) identifier, and the vendor has not shared any technical details about the vulnerability itself. Despite the lack of public information, PaperCut warned in a security bulletin that the issue is being exploited.

The vendor released emergency patches on Friday and strongly urged customers to install them without delay. In addition to patching, PaperCut recommends disconnecting the application server from the internet and restricting access to trusted IP addresses as immediate mitigation measures.

Confirmed Customer Incidents

“We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” the company said in an advisory. The statement is the only official public comment from PaperCut so far, and it does not identify the number of affected customers or the timeline of the attacks.

It is unclear who is behind the exploitation. No threat group has claimed responsibility, and no attribution has been provided by the vendor or any external researchers.

IoCs: pc-app.exe and Log Tampering

PaperCut has shared some indicators of compromise (IoCs) to help defenders detect potential intrusions. One notable indicator is the presence of a suspicious file named pc-app.exe, which suggests that attackers are delivering malware or other post-exploitation tools after exploiting the vulnerability.

The company also noted that unexpectedly truncated or deleted server.log files could indicate an intrusion. The removal or modification of log files can suggest that attackers are attempting to cover their tracks, a common tactic after gaining access.

Organizations using PaperCut should check for these signs and review their logs for any anomalies, especially if they have not yet applied the patch.

Prior PaperCut Flaws in KEV

This is not the first time a PaperCut NG/MF vulnerability has been exploited in the wild. The Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog includes three PaperCut flaws, and this latest weakness has not yet been added to the list. The KEV catalog is used by federal agencies and other organizations to prioritize patching.

Two of the security holes already included in the KEV list have been exploited in ransomware attacks, making PaperCut a known target for financially motivated threat actors. The new zero-day, if successfully exploited, could give attackers a foothold in enterprise networks that rely on print management systems.

Internet Exposure Data

Roughly 1,000 PaperCut instances are currently exposed to the internet, with a majority in North America and Europe, according to data from the ShadowServer Foundation. This exposure gives attackers a wide pool of potential targets, and the active exploitation of the zero-day raises the stakes for organizations that have not yet applied the emergency patches.

  • Roughly 1,000 PaperCut instances are exposed to the internet.
  • Three PaperCut flaws are listed in CISA's KEV catalog.
  • Two of those KEV-listed flaws have been exploited in ransomware attacks.

Patch Now, Disconnect if Possible

The vendor's advisory urges customers to install the emergency patches immediately. For organizations that cannot patch right away, PaperCut recommends disconnecting the application server from the internet and restricting access to trusted IP addresses as interim measures. These steps can reduce the attack surface while the patch is being deployed.

Administrators should also review their systems for the IoCs shared by PaperCut, such as pc-app.exe and unusual log activity, to determine if they may have been compromised.

Why This Matters

The active exploitation of this zero-day, combined with the historical ransomware attacks against PaperCut vulnerabilities, underscores the critical need for organizations using NG/MF to prioritize patch management. With roughly 1,000 internet-exposed instances, the attack surface is significant, and delaying the patch could leave systems vulnerable to compromise. This incident also highlights the broader challenge of defending against zero-days when attackers move quickly to exploit them before vendors can release fixes and before CISA adds them to the KEV catalog.

#papercut#zero-day#cve#patch#kev

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories