Overview
PaperCut has issued an urgent warning: attackers are actively exploiting a zero‑day vulnerability impacting all versions of PaperCut NG and MF print management software. The company has released emergency patches for v25 and v26 and confirmed customer incidents are already under investigation.
Indicators of Compromise (IoCs)
Administrators should watch for:
- Suspicious activity from
pc-app.exeflagged by intrusion detection or endpoint monitoring tools. - Missing or altered logs: Unexpectedly truncated or deleted
server.logfiles. - Error entries in
server.log:ERROR No suitable driver found for jdbc:no:xERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
Exploitation Context
- The vulnerability details remain undisclosed, but internet‑exposed PaperCut servers are at highest risk.
- PaperCut urges customers to restrict access to trusted IP addresses immediately.
- Firewall rules and network access controls should be applied to block untrusted connections.
Historical Precedent
This is not the first time PaperCut has been targeted:
- In 2023, CVE‑2023‑27350 (CVSS 9.8) was exploited by Russian threat actors and the Lace Tempest group, delivering Cl0p and LockBit ransomware.
- The current zero‑day raises concerns of similar ransomware deployment or data theft.
Defensive Guidance
Organizations should:
- Apply emergency patches: Upgrade to patched v25/v26 builds immediately.
- Restrict exposure: Ensure PaperCut web interfaces are not reachable from untrusted networks.
- Monitor logs: Investigate missing or suspicious entries in
server.log. - Hunt for persistence: Review endpoint and network activity for signs of lateral movement.
Expert in the Cloud Insight
This zero‑day highlights how enterprise print management systems can become high‑value attack surfaces. With confirmed exploitation already underway, the lesson is clear: patching and network segmentation must be immediate priorities. Print servers often sit at the intersection of IT and business workflows — making them attractive targets for ransomware operators and advanced threat groups.
Leave a Reply