PaperCut has issued an urgent security advisory after confirming that attackers are actively exploiting a vulnerability in its PaperCut NG and PaperCut MF print-management products.
The company said it has received reports of customer incidents and is treating the issue as a high-priority security emergency. The vulnerability affects all versions of PaperCut NG and PaperCut MF.
Although PaperCut has not yet publicly disclosed full technical details of the flaw, its incident response team said it reproduced the vulnerability using information provided by a university customer, its security team, and a digital forensics and incident response provider.
PaperCut NG/MF Vulnerability Exploited
Organizations operating an internet-accessible PaperCut Application Server have been told to immediately restrict web access to trusted internal IP addresses.
The vendor stressed that administrators should take this step even when they have not identified suspicious activity. Public-facing PaperCut infrastructure should be considered particularly exposed until access controls are applied and emergency updates have been deployed.
PaperCut released emergency patches for PaperCut NG and PaperCut MF versions 25 and 26 at 02:10 a.m. AEST on August 28. The builds are intended for customers with externally accessible PaperCut deployments that cannot promptly apply alternative mitigations.
For PaperCut MF, the emergency releases are version 26.0.4.76494 and version 25.0.12.76496. PaperCut NG customers should deploy version 26.0.4.76495 or version 25.0.12.76497, depending on their existing major release. Installers are available for Windows, Linux, and macOS.
PaperCut emphasized that these are emergency releases and that they did not undergo the vendor’s usual software release process.
The company is continuing to investigate the incident and said it will publish more verified details, including additional indicators of compromise and remediation guidance.
A patch for PaperCut NG/MF version 24 remains in development. PaperCut recommends that organizations upgrade to the latest supported version whenever practical, particularly where print-management servers are exposed to the internet or accessible from less-trusted network segments.
Defenders should investigate alerts involving the PaperCut Application Server, especially suspicious post-exploitation activity associated with the pc-app.exe process. Other potential compromise indicators include missing, unexpectedly truncated, or deleted PaperCut server.log files.
PaperCut also identified two log messages that may warrant investigation: ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
The company cautioned that the lack of these entries does not confirm that a server has not been compromised.
Administrators should preserve available PaperCut logs and examine endpoint, network, proxy, firewall, authentication, and database telemetry for unusual behavior.
Security teams should look for unexpected processes spawned by PaperCut services, suspicious outbound network connections, authentication anomalies, altered configurations, or irregular database-query activity.
The patch introduces an operational consideration for organizations that use Card/ID number lookups from an external database. Patched builds will reject SQL queries containing EXEC, EXECUTE, or CALL statements within that feature.
Organizations using these integrations should review their configurations and test compatible query changes as part of remediation.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN



