PaperCut is warning customers that a vulnerability affecting every version of its PaperCut NG and PaperCut MF print management software is being actively exploited in zero-day attacks. The company says it has confirmed real-world incidents and is treating the situation as its highest priority.

In an urgent security advisory published Thursday, PaperCut’s security response team said it is investigating active exploitation and reproduced the vulnerability using details supplied by a university customer. The company has not disclosed technical specifics of the flaw or how attackers are exploiting it, but confirmed the issue impacts all versions of NG and MF.

PaperCut has released emergency patches for v25 and v26, describing them as intended for organizations running public-facing PaperCut Application Servers that cannot immediately apply other mitigations. Administrators who cannot patch right away are being told to use firewall rules or network access controls to restrict web interface access to trusted IP addresses only.

Indicators of Compromise

PaperCut shared several indicators that may suggest a server has been compromised, including suspicious activity originating from the legitimate pc-app.exe process, and server.log files that have been modified, deleted, or are missing entirely. Administrators should also check server.log for these errors:

  • ERROR No suitable driver found for jdbc:no:x
  • ERROR DatabaseUtils – Database error looking up cardID: VALUES CAST

PaperCut cautioned that the absence of these indicators does not rule out compromise. The company has not disclosed who is behind the attacks, what actions attackers take after gaining access, or whether data theft is occurring. It says the advisory will be updated with further indicators and remediation guidance as the investigation continues.

A Recurring Target

PaperCut has a history of being targeted following vulnerability disclosures. In April 2023, attackers exploited the critical CVE-2023-27350 flaw, which allowed unauthenticated remote code execution. Microsoft linked subsequent attacks to the Clop and LockBit ransomware operations, as well as Iranian state-backed groups, while CISA and the FBI warned that the Bl00dy Ransomware Gang exploited the same flaw against the education sector.

Organizations running PaperCut NG or MF should apply the emergency patches immediately, restrict internet exposure of Application Servers, and review logs for the published indicators of compromise while awaiting further guidance from PaperCut.