PaperCut is sounding an urgent alarm, revealing that malicious actors are actively exploiting a critical zero-day vulnerability that affects all versions of its widely-used PaperCut NG and PaperCut MF print management software. The company has confirmed instances of successful attacks against its customers and is strongly advising organizations with internet-exposed PaperCut Application Servers to immediately implement access restrictions, limiting web interface access solely to trusted IP addresses. This development marks another significant cybersecurity threat for organizations relying on PaperCut’s solutions, especially given the software’s prevalence in enterprise and educational environments.
Immediate Threat: Active Exploitation and Zero-Day Vulnerability
In an urgent security advisory released on Thursday, the PaperCut Software security response team confirmed the ongoing exploitation of this undisclosed vulnerability. The advisory states, "PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. We are aware of confirmed customer incidents and are treating this matter with the highest priority." While the company has not yet divulged specific technical details about the flaw or the precise methods attackers are employing, the acknowledgment of "confirmed customer incidents" underscores the immediate and tangible danger posed to its user base.
The vulnerability is reported to impact all versions of both PaperCut NG (Next Generation) and PaperCut MF (Multi-Function), indicating a broad potential attack surface. This lack of version specificity means that even older, potentially unpatched installations are at risk. PaperCut’s security team has been able to reproduce the vulnerability internally, leveraging information initially provided by a university customer, which highlights the sophisticated nature of the discovery and the rapid response required.
Emergency Response and Mitigation Strategies
In response to the escalating threat, PaperCut has expedited the release of emergency patches specifically for customers whose PaperCut NG/MF servers are publicly accessible. The advisory clearly designates these patches as "an emergency patch for customers with public-facing PaperCut NG/MF servers who are unable to take other mitigating action." This implies that patching should be the primary course of action for those with exposed servers, as other network-level controls might not be sufficient against a zero-day exploit.

Beyond patching, PaperCut continues to strongly recommend that organizations with internet-exposed Application Servers implement robust firewall rules and network access controls. The goal is to strictly limit access to the web interfaces, ensuring that only authorized and trusted IP addresses can connect. This layered security approach is crucial, as it can act as a secondary defense mechanism even if the primary vulnerability is not immediately patched.
Indicators of Compromise and Detection
To aid organizations in identifying potential breaches, PaperCut has shared a list of indicators of compromise (IOCs). These can help administrators determine if their systems have already been compromised. Key indicators include:
- Suspicious Activity from
pc-app.exe: The legitimate PaperCut application executable (pc-app.exe) exhibiting unusual or unexpected behavior can be a strong signal of malicious activity. This might involve processes running when they shouldn’t, unusual network connections originating from the process, or unexpected resource consumption. - Tampered
server.logFiles: Log files are critical for security auditing. Modifications, deletions, or outright missingserver.logfiles are highly suspicious. Attackers often attempt to erase their tracks by manipulating logs to hide their presence and actions. - Specific Database Errors: Administrators are advised to scrutinize
server.logfor specific error messages that could indicate exploitation. These include:ERROR No suitable driver found for jdbc:no:xERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
However, PaperCut issues a crucial caveat: the absence of these specific indicators does not guarantee that a server has not been compromised. Sophisticated attackers can employ techniques to avoid detection or manipulate logs in more subtle ways. Therefore, a proactive and vigilant security posture is essential.
Unanswered Questions and Ongoing Investigation
As of the latest updates, PaperCut has not disclosed the identity of the threat actors behind these attacks, nor have they provided details on the post-exploitation activities or whether data theft has occurred. The nature of zero-day exploits often means that the full scope and impact of the attack are not immediately clear. PaperCut has pledged to continue updating its security advisory with additional IOCs and remediation guidance as its investigation progresses.
BleepingComputer has reached out to PaperCut for further details regarding the exploitation and will update its reporting as more information becomes available. The lack of transparency regarding the attackers and their motives leaves organizations to prepare for a range of potential threats, from ransomware to data exfiltration and disruption.

Historical Context: A Recurring Target
This latest incident is not an isolated event for PaperCut. The company has a documented history of being targeted by threat actors following the disclosure of security vulnerabilities. This recurring pattern underscores the importance of prompt patching and robust security practices for organizations using its software.
- April 2023: CVE-2023-27350 Exploitation: In April 2023, attackers began actively exploiting a critical vulnerability, CVE-2023-27350. This flaw allowed unauthenticated attackers to bypass security measures and execute arbitrary code remotely on vulnerable PaperCut servers.
- Link to Major Ransomware Operations: Microsoft subsequently linked some of these 2023 attacks to the Clop ransomware operation. Clop leveraged the PaperCut vulnerability for initial access into company networks, a common tactic to establish a foothold before deploying their ransomware. Microsoft also observed intrusions that subsequently led to LockBit ransomware attacks, highlighting the widespread impact of this vulnerability across the threat landscape.
- Data Exfiltration vs. Initial Access: While PaperCut’s Print Archiving feature can retain documents processed through its servers, Clop representatives clarified to BleepingComputer that their primary objective with the CVE-2023-27350 exploit was initial network access, not necessarily direct exfiltration of archived documents from PaperCut itself. This distinction is important for understanding attacker motivations.
- State-Sponsored Actors and Other Groups: The exploitation of CVE-2023-27350 was not limited to ransomware groups. Microsoft also reported that Iranian state-backed hacking groups were actively exploiting this vulnerability, demonstrating its appeal to a diverse range of threat actors.
- Education Sector Targeted: In May 2023, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a joint advisory warning that the Bl00dy Ransomware Gang was also exploiting vulnerable PaperCut servers, particularly targeting organizations within the education sector. This highlights the significant risk posed to institutions that often handle sensitive student and research data.
The history of these past exploits suggests that PaperCut servers are a valuable target for cybercriminals due to their widespread deployment in environments that can be rich in data and provide access to critical infrastructure.
Broader Implications for Cybersecurity Posture
The active exploitation of a zero-day vulnerability in a widely deployed software like PaperCut NG/MF has several critical implications for organizations:
- Supply Chain Risk: This incident highlights the inherent risks associated with software supply chains. A vulnerability in a single, widely adopted application can have a cascading effect, impacting thousands of organizations. This underscores the need for thorough vendor risk management and the ability to rapidly respond to third-party security advisories.
- Zero-Day Threat Landscape: The continuous emergence of zero-day exploits emphasizes the limitations of signature-based security solutions. Organizations must invest in advanced threat detection capabilities, behavioral analysis, and proactive threat hunting to identify and respond to novel threats before they can cause significant damage.
- Importance of Network Segmentation and Access Control: The repeated advice from PaperCut to restrict access to internet-exposed interfaces reinforces the fundamental cybersecurity principle of least privilege and network segmentation. Limiting the attack surface by restricting external access to internal services is a critical defense-in-depth strategy.
- Incident Response Preparedness: This event serves as a stark reminder of the need for well-defined and regularly tested incident response plans. Organizations must have clear procedures for identifying, containing, eradicating, and recovering from security incidents, especially those involving zero-day exploits where immediate external guidance might be limited.
- Patch Management Urgency: While emergency patches are available, the delay in applying them can be critical. This emphasizes the need for agile and efficient patch management processes, particularly for internet-facing systems and critical software. Organizations that cannot patch immediately must have robust compensating controls in place.
The ongoing investigation by PaperCut and the continuous flow of information from cybersecurity researchers will be crucial in understanding the full scope of this threat. In the interim, organizations using PaperCut NG or PaperCut MF, especially those with servers accessible from the internet, must prioritize the implementation of the recommended mitigation strategies, including immediate patching and strict access controls, to protect their networks and data from active exploitation. The cybersecurity landscape remains dynamic, and proactive vigilance is the most effective defense against evolving threats.








