PaperCut Zero‑Day Exploited

Overview

PaperCut has issued an urgent warning: attackers are actively exploiting a zero‑day vulnerability impacting all versions of PaperCut NG and MF print management software. The company has released emergency patches for v25 and v26 and confirmed customer incidents are already under investigation.

Indicators of Compromise (IoCs)

Administrators should watch for:

  • Suspicious activity from pc-app.exe flagged by intrusion detection or endpoint monitoring tools.
  • Missing or altered logs: Unexpectedly truncated or deleted server.log files.
  • Error entries in server.log:
    • ERROR No suitable driver found for jdbc:no:x
    • ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Exploitation Context

  • The vulnerability details remain undisclosed, but internet‑exposed PaperCut servers are at highest risk.
  • PaperCut urges customers to restrict access to trusted IP addresses immediately.
  • Firewall rules and network access controls should be applied to block untrusted connections.

Historical Precedent

This is not the first time PaperCut has been targeted:

  • In 2023, CVE‑2023‑27350 (CVSS 9.8) was exploited by Russian threat actors and the Lace Tempest group, delivering Cl0p and LockBit ransomware.
  • The current zero‑day raises concerns of similar ransomware deployment or data theft.

Defensive Guidance

Organizations should:

  • Apply emergency patches: Upgrade to patched v25/v26 builds immediately.
  • Restrict exposure: Ensure PaperCut web interfaces are not reachable from untrusted networks.
  • Monitor logs: Investigate missing or suspicious entries in server.log.
  • Hunt for persistence: Review endpoint and network activity for signs of lateral movement.

Expert in the Cloud Insight

This zero‑day highlights how enterprise print management systems can become high‑value attack surfaces. With confirmed exploitation already underway, the lesson is clear: patching and network segmentation must be immediate priorities. Print servers often sit at the intersection of IT and business workflows — making them attractive targets for ransomware operators and advanced threat groups.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.