PaperCut Zero-Day Actively Exploited Across All Versions
A critical zero-day vulnerability in PaperCut print management software is under active attack. Emergency patches are available for the latest versions.
TL;DR
- Attackers are exploiting a zero-day in all PaperCut NG and MF versions
- Confirmed incidents have been reported by the vendor
- Emergency patches released for v25 and v26 only
- Organizations should immediately apply updates or isolate affected systems
- The vulnerability allows unauthorized access to networked printers
PaperCut has confirmed that a critical zero-day vulnerability is being actively exploited across all versions of its NG and MF print management software. The company has issued an emergency security advisory after detecting confirmed customer incidents involving unauthorized access through the vulnerability.
The vulnerability affects organizations running PaperCut's widely-deployed print management solutions, which are commonly used in enterprise and educational environments. Attackers have been leveraging the flaw to gain unauthorized network access, potentially compromising connected printing infrastructure and associated systems.
Vulnerability Details
- Affects all versions of PaperCut NG and PaperCut MF print management software
- Classified as a zero-day with active exploitation in the wild
- Allows unauthorized remote access to networked printing systems
- No public exploit details have been disclosed by the vendor
Response and Mitigation
- Emergency patches released for PaperCut v25 and v26 versions only
- Organizations running older versions should isolate affected systems immediately
- Vendor recommends monitoring for unusual print job activity or unauthorized access
- Customers should review network segmentation around print management infrastructure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.