PaperCut Urges Immediate Patching as Zero-Day Vulnerability Actively Exploited
Print management software provider **PaperCut** is issuing an urgent security advisory regarding a zero-day vulnerability actively being exploited in **PaperCut NG** and **PaperCut MF**. Organizations with internet-exposed application servers are advised to restrict access immediately and apply emergency patches.

**PaperCut** has issued a critical warning about a newly discovered zero-day vulnerability affecting all versions of its **PaperCut NG** and **PaperCut MF** print management software. The company confirms active exploitation in the wild and urges immediate action from customers.
### Urgent Call to Action
In an urgent security advisory, **PaperCut** stated, "**PaperCut Software** security response team is investigating active exploitation of a vulnerability affecting **PaperCut NG** and **PaperCut MF**." The company is aware of confirmed customer incidents and is treating the matter with the highest priority.
Organizations with **PaperCut Application Servers** exposed to the internet are strongly advised to restrict web interface access to trusted IP addresses using firewall rules or network access controls.
### Vulnerability Details and Emergency Patches
While **PaperCut** has not yet disclosed specific details about the vulnerability or its exploitation method, the company confirmed that its security team successfully reproduced the flaw based on information provided by a university customer. Emergency patches have been released for customers with public-facing **PaperCut NG/MF** servers who cannot implement other mitigating actions.
### Indicators of Compromise (IoCs)
**PaperCut** has provided several indicators of compromise (IoCs) to help administrators identify potential breaches:
* Suspicious activity originating from the legitimate **PaperCut** `pc-app.exe` process.
* `server.log` files that show signs of modification, deletion, or are missing entirely.
* Specific error messages in `server.log`, such as:
It is important to note that the absence of these indicators does not definitively mean a server has not been compromised. **PaperCut** has not yet disclosed information about the attackers' identities, their post-compromise activities, or whether data exfiltration is occurring. The company plans to update its advisory with further IoCs and remediation guidance as its investigation progresses.
### A History of Targeted Exploitation
This is not the first time **PaperCut** vulnerabilities have been targeted by threat actors. In April 2023, a critical vulnerability, **CVE-2023-27350**, was widely exploited. This flaw allowed unauthenticated attackers to bypass authentication and execute code remotely on vulnerable servers.
**Microsoft** subsequently linked some of these attacks to the **Clop** ransomware operation, which leveraged vulnerable **PaperCut** servers for initial network access. **LockBit** ransomware attacks were also observed using similar intrusion methods. While **PaperCut** has a print archiving feature, **Clop** reportedly used the vulnerability for network access rather than directly stealing archived documents.
The exploitation of **CVE-2023-27350** expanded to include other significant threat actors. **Microsoft** reported that Iranian state-backed hacking groups were also exploiting the vulnerability. Furthermore, **CISA** and the **FBI** issued a joint advisory in May 2023, warning that the **Bl00dy Ransomware Gang** was targeting the education sector with attacks against vulnerable **PaperCut** servers.