- Attackers are currently targeting a security vulnerability in PaperCut NG/MF, a print management software. There is no concrete information about the vulnerability yet, but secured versions are available for download.
- Currently, there is no CVE number for the vulnerability, and an assessment of the threat level is pending.
- The developers have fixed versions v25 and v26 for Linux, macOS, and Windows, with v24 expected to follow.
- The extent of the attacks is currently unknown, and the specific impact of the vulnerability is unclear. Due to the urgent warning from developers, the danger is obviously very high.
- The developers have provided initial Indicators of Compromise (IoC) to help identify attacked systems, but they explicitly note that systems can still be compromised even if none of the IoCs are found.
- In addition to installing the security patch, admins are advised to restrict access via firewall rules to trusted devices if instances are publicly accessible.
- The developers intend to update the warning message later with more IoCs.
- Admins should look for suspicious activities in the context of the PaperCut Application Server, especially pc-app.exe, deleted logs, and specific log entries such as ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
Attackers are exploiting a zero-day vulnerability in all versions of PaperCut NG/MF print management software, leading to emergency patches for versions 25 and 26, with version 24 expected to follow. The developers have issued urgent warnings, stating they are aware of confirmed customer incidents and are treating the matter with the highest priority.12
Currently, there is no CVE number for the vulnerability, and the specifics of the flaw remain undisclosed. The extent of the attacks is unknown, and it is unclear what actions attackers can take after a successful breach. The developers have provided initial indicators of compromise (IoCs) to help admins identify affected systems, but they caution that systems may still be compromised even if no IoCs are detected.38
Admins are advised to restrict access to the PaperCut Application Server, especially for those exposed to the internet, by implementing firewall rules and network access controls. PaperCut emphasized, "Take this action now, even if you have not observed suspicious activity." The company is conducting an ongoing investigation into the incident and plans to update the warning message with more IoCs.79
In 2023, a previous vulnerability in PaperCut MF and NG was exploited by Russian threat actors and a financially motivated group to deliver ransomware, highlighting the ongoing risks associated with this software.
“The developers have provided initial Indicators of Compromise, including suspicious activity around pc-app.exe and specific log errors, but warn that systems may still be compromised even if none are found. Admins are advised to apply firewall rules restricting access to trusted devices if instances are publicly accessible.”










