0 Comments

If you run PaperCut print management software, stop what you are doing and read this. PaperCut has confirmed that an unpatched vulnerability in all versions of PaperCut NG and PaperCut MF is being actively exploited in the wild. Emergency patches are now available for v25 and v26, but the clock is ticking — attackers are already hitting exposed servers.

What Is Happening

On August 27, 2026, PaperCut security team issued an urgent advisory after a university customer incident response team helped them reproduce a vulnerability in the code. The company is treating this with the highest priority and has confirmed multiple customer compromises. While the exact technical details of the flaw are being withheld to give defenders time to patch, the exploitation is real and ongoing.

This is not PaperCut first rodeo with attackers. In April 2023, the critical CVE-2023-27350 vulnerability was exploited en masse by the Clop ransomware operation, followed by LockBit ransomware, and even Iranian state-backed hacking groups. The Bl00dy Ransomware Gang specifically targeted the education sector through vulnerable PaperCut servers. That history makes this new zero-day especially concerning — threat actors already have proven playbooks for weaponizing PaperCut flaws.

Affected Systems

This vulnerability affects every version of PaperCut NG and PaperCut MF. If you have a PaperCut Application Server with its web interfaces exposed to the public internet, you are in the crosshairs. Emergency patches have been released for v25 and v26, with patches for v24 still in progress. PaperCut strongly recommends upgrading to the latest version if you are running anything older.

How the Attack Works

PaperCut has not publicly disclosed the exploitation mechanism, but the indicators of compromise point to the legitimate pc-app.exe process being abused. Administrators should look for suspicious activity from this process — attackers appear to be leveraging it for post-exploitation actions. The server.log file may show telltale errors:

ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

However, PaperCut warns that the absence of these indicators does not mean your server is clean. Attackers may be deleting or modifying log files to cover their tracks.

What Attackers Are After

At this stage, PaperCut has not disclosed the full scope of post-exploitation activity. Given the 2023 attacks, ransomware deployment is a realistic concern. Print servers are valuable initial access points because they sit inside corporate networks with access to domain credentials, file shares, and other sensitive systems. The 2023 incidents saw Clop and LockBit using PaperCut as a beachhead to deploy ransomware across entire organizations.

Immediate Mitigation Steps

Step 1: Restrict network access immediately. If your PaperCut Application Server web interface is accessible from the internet, block it now. Use firewall rules or network access controls to restrict access to trusted internal IP addresses only. This is the single most effective mitigation.

Step 2: Apply the emergency patch. Download the emergency patch for your version from PaperCut advisory page. Patches are available for PaperCut NG and MF v25 and v26. If you are on v24, upgrade to v25 or v26 and patch immediately.

Step 3: Check for indicators of compromise. Review your server.log files for the errors listed above. Check for missing, truncated, or recently deleted log files. Monitor for unusual activity from the pc-app.exe process. However, remember that a clean check does not guarantee your server is uncompromised.

Step 4: Escalate to incident response if needed. If you find any indicators of compromise, treat this as a potential breach. Engage your incident response team and consider forensic analysis of the affected server.

The Bottom Line

This is an active, ongoing attack against a widely deployed print management platform with a documented history of ransomware exploitation. The emergency patch is out, but the most critical action is closing off internet access to your PaperCut web interface. Do not wait — attackers are already scanning for exposed servers. If you run PaperCut, take action now.

Leave a Reply

Related Posts