PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday.

“We are aware of confirmed customer incidents and are treating this matter with the highest priority.”
PaperCut says the vulnerability affects all versions of PaperCut NG and MF, but has not shared details about the flaw or how it is being exploited.
The company says its security team reproduced the vulnerability using information provided by a University customer.
PaperCut has now released emergency patches for customers with public-facing PaperCut NG/MF servers.
“This is an emergency patch for customers with public-facing PaperCut NG/MF servers who are unable to take other mitigating action,” reads the advisory.
The company continues to warn customers whose Application Servers are exposed to the Internet to use firewall rules or network access controls to restrict their web interfaces to trusted IP addresses.
PaperCut also shared indicators of compromise that could indicate whether a server has been compromised.
These include suspicious activity from the the legitimate PaperCut pc-app.exe process and server.log files that have been modified, deleted, or are missing.
Administrators should also look for the following errors in server.log:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CASTHowever, PaperCut warns that a lack of indicators does not mean that a server has not been compromised.
At this time, PaperCut has not disclosed who is behind the attacks, what attackers are doing after compromising servers, or whether data is being stolen.
PaperCut says it will continue updating its advisory with additional indicators of compromise and remediation guidance as its investigation continues.
BleepingComputer contacted PaperCut with questions about this exploitation and will update the story when we receive a response.
Previous PaperCut flaws exploited in attacks
PaperCut has a history of being targeted by threat actors after security vulnerabilities were disclosed.
In April 2023, attackers began exploiting the critical CVE-2023-27350 PaperCut vulnerability, which allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers.
Microsoft later linked some of those attacks to the Clop ransomware operation, which exploited vulnerable PaperCut servers for initial access to company networks. Microsoft also observed intrusions that led to LockBit ransomware attacks.
While PaperCut has a Print Archiving feature that can retain documents sent through a server, Clop later told BleepingComputer that it had used the vulnerabilities for initial access to victim networks rather than to steal archived documents directly from PaperCut servers.
The exploitation spread to other threat actors, with Microsoft reporting that Iranian state-backed hacking groups were also exploiting CVE-2023-27350.
CISA and the FBI issued a joint advisory in May 2023 warning that the Bl00dy Ransomware Gang was also exploiting vulnerable PaperCut servers in attacks against the education sector.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

