PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild.

The vulnerability has not yet been assigned a CVE identifier and no technical details have been shared. The vendor released emergency fixes on Friday and urged customers to install them.

PaperCut also recommends disconnecting the application server from the Internet and restricting access to trusted IP addresses.

“We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” the company said in its consultative.

It is not clear who is behind exploiting the zero-day vulnerability.

PaperCut shared some Indicators of Compromise (IoC), including suspicious activity related to pc-app.exethe main executable for the PaperCut application server.

Advertising. Scroll to continue reading.

The company also noted that unexpectedly shortened or deleted server.log files may indicate intrusion. Removing or modifying log files may suggest that attackers are trying to cover their tracks.

This is not the first PaperCut NG/MF vulnerability exploited in the wild. Known CISA Exploited Vulnerabilities (KEV) catalog includes three weaknesses and this last weakness has not been added.

Two of the security holes listed by KEV have been used in ransomware attacks.

There are currently approximately 1,000 instances of PaperCut exposed on the Interneta majority in North America and Europe, according to data from the ShadowServer Foundation.

UPDATE: Huntress published a blog post describing attacks observed against two client environments. The company noted that the vulnerability “gives an unauthorized attacker remote control over the trusted configuration of PaperCut, which could be used to execute arbitrary Java code in the application process.”

UPDATE 2: The identifiers CVE-2026-81578 and CVE-2026-82078 have been assigned to the vulnerability.

Connected: Recent Citrix NetScaler Vulnerability Exploited in the Wild

Connected: Adobe and Nvidia fix dozens of vulnerabilities

Connected: CISA warns of exploited Gitea vulnerability

Leave a Reply

Your email address will not be published. Required fields are marked *