PaperCut Releases Emergency Patch for Exploited Zero-Day
PaperCut NG/MF users urged to patch zero-day vulnerability exploited in the wild.
Summary
PaperCut Software has released an emergency patch for a zero-day vulnerability affecting its NG and MF print management solutions. The flaw is actively being exploited in the wild, though a CVE identifier has not yet been assigned. PaperCut recommends immediate patching, disconnecting affected servers from the internet, and restricting access to trusted IPs, as confirmed customer incidents have been reported.
Full text
PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild. The flaw has yet to be assigned a CVE identifier and no technical details have been shared. The vendor released emergency patches on Friday and urged customers to install them. PaperCut also recommends disconnecting the application server from the internet and restricting access to trusted IPs. “We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” the company said in its advisory. It’s unclear who is behind the exploitation of the zero-day vulnerability. PaperCut has shared some indicators of compromise (IoCs), including the name of a suspicious file, pc-app.exe, which indicates that the attackers are delivering malware or other post-exploitation tools. Advertisement. Scroll to continue reading. The company also noted that unexpectedly truncated or deleted server.log files could indicate an intrusion. The removal or modification of log files can suggest that attackers are attempting to cover their tracks. This is not the first PaperCut NG/MF vulnerability exploited in the wild. CISA’s Known Exploited Vulnerabilities (KEV) catalog includes three flaws, and this latest weakness has not been added. Two of the security holes included in the KEV list have been exploited in ransomware attacks. Roughly 1,000 PaperCut instances are currently exposed to the internet, a majority in North America and Europe, according to data from the ShadowServer Foundation. Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild Related: Adobe and Nvidia Patch Dozens of Vulnerabilities Related: CISA Warns of Exploited Gitea Vulnerability Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Recent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation Latest News Trump Order Aims to Block Foreign Backdoors in US Power Grid GearAustralia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity SecurityCISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-SuiteCyberattack Causes Global Disruption at Boston ScientificThe Future of AI-Driven Security Depends on Complete DataUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — pc-app.exe