Print management vendor PaperCut confirms active exploit spree

PaperCut Software confirmed active attacks on an unspecified vulnerability in its NG and MF print management products.

CSBadmin
1 Min Read

Print management vendor PaperCut Software has confirmed customer incidents tied to an unknown flaw in its NG and MF products. The company says the vulnerability is under active attack.

The vendor’s guidance treats the flaw as remotely exploitable. It tells admins to lock down any Application Server reachable from the public internet, restricting web access to trusted IP addresses only.

PaperCut NG manages printing for offices and schools, while MF adds support for multifunction copiers. The Application Server is the central component of both products, and there is normally one per organization, making it a high-value target.

The vendor is still investigating and says it will publish specific indicators of compromise once identified. In the meantime, admins should watch for endpoint or network alerts tied to the Application Server, especially post-exploitation activity from pc-app.exe, missing or truncated server.log files, and specific JDBC database errors in the logs.

PaperCut has been targeted before: a critical remote code execution flaw in the same products was exploited at scale in 2023. Security teams should treat this as urgent and assume any internet-facing Application Server is at risk, even before official indicators arrive.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.