PaperCut issues emergency patches after active zero-day

PaperCut released emergency updates for NG and MF after confirming a zero-day is being actively exploited; customers are urged to apply patches and limit external access now.

PaperCut Software released emergency patches on Friday for its NG and MF print-management products after confirming a zero-day vulnerability is being actively exploited in the wild. The vendor reported confirmed customer incidents and said its investigation is ongoing. No CVE identifier has been assigned and the company has not published technical details about the flaw.

PaperCut advised customers to disconnect application servers from the internet or restrict access to trusted IP addresses while they install the updates. The company instructed organizations to prioritize the emergency update and apply the fixes immediately.

The vendor provided a short list of indicators of compromise to customers, including a suspicious filename, pc-app.exe, which suggests attackers may be delivering malware or other post-exploitation tools to compromised systems. PaperCut also warned that unexpectedly truncated or deleted server.log files can signal intrusion and attempts to erase evidence.

Attribution for the exploitation is unknown. PaperCut has not released exploit details that would allow outside researchers to reproduce or fully analyze the vulnerability. The flaw is not yet included in the U.S. Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog.

Telemetry from the ShadowServer Foundation indicates roughly 1,000 PaperCut instances are reachable from the public internet, with the largest concentrations in North America and Europe. Those exposed systems may be at greater risk until the patches are applied and external access is limited.

CISA’s catalog lists three past PaperCut flaws, and two of those earlier vulnerabilities were tied to ransomware incidents. PaperCut NG and MF have been the subject of prior exploitation events documented by national authorities.

Customers were asked to search systems for the provided indicators such as pc-app.exe, inspect server logs for signs of tampering, and follow PaperCut’s guidance on restricting network access while forensic work continues. In its advisory, PaperCut wrote: “We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing.”

Security teams are monitoring for additional technical details from PaperCut and for any further guidance from national cybersecurity authorities that could provide mitigation steps or deeper analysis.

Articles by this author