PaperCut print servers under active attack via unpatched flaw

PaperCut says hackers are breaking into print management servers using a bug that affects every version of NG and MF. Emergency patches are out.

ThreatVectr Newsdesk· 4 min read
Gogs Git service interface on a computer screen, showing coding activity, with a focus on security vulnerabilities
Share

Key points

  • PaperCut confirmed on Thursday that hackers are actively exploiting a previously unknown flaw in every version of its PaperCut NG and PaperCut MF print management software.
  • The company has issued an emergency patch for customers whose PaperCut servers are reachable from the public internet.
  • PaperCut has not said who is behind the attacks, what the attackers do once inside, or whether any data has been stolen.
  • Administrators are told to lock the web interface down to trusted IP addresses and check server logs for specific error messages.
  • The same product was hit hard in 2023, when the Clop and LockBit ransomware crews used a different PaperCut bug to break into corporate networks.

PaperCut, the Australian maker of print management software used by universities, hospitals and large offices, says criminals are actively breaking into its servers using a zero-day, meaning a software flaw the vendor did not know about until attacks started.

The company published an urgent advisory on Thursday saying its security team is "investigating active exploitation" and is "aware of confirmed customer incidents." It reproduced the bug using details supplied by a university customer that was attacked.

Every version of PaperCut NG and PaperCut MF is affected. The company has not published a CVE identifier, a CVSS score, or a technical description of the flaw yet. (That is unusual for a live exploitation advisory, and worth flagging.)

What should PaperCut customers do right now?

Install the emergency patch and get the web interface off the open internet. PaperCut has released a fix aimed specifically at customers whose Application Servers, the machine that runs the admin console, are reachable from anywhere on the internet.

If patching immediately is not possible, PaperCut wants administrators to use firewall rules or network access controls so that only trusted IP addresses can reach the web interface. That single change would take most exposed servers out of the line of fire.

The advisory also lists indicators of compromise, meaning signs that a server has already been broken into. Admins should look for:

  • Suspicious activity coming from the legitimate pc-app.exe process.
  • server.log files that have been modified, deleted, or are missing entirely.
  • Two specific error strings in server.log: ERROR No suitable driver found for jdbc:no:x and ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.

PaperCut warns that a clean log does not mean a clean server. Attackers may be wiping traces.

Who is being targeted?

PaperCut has not named the attackers or their motive. The only detail confirmed so far, first reported by BleepingComputer, is that a university customer supplied the information that let PaperCut reproduce the bug. Whether the attackers are after ransomware access, stored print jobs, or something else is not yet known.

The product's install base is large. Universities, school districts, and healthcare providers are common PaperCut users, and those sectors have been hit repeatedly through this vendor before.

Has this happened to PaperCut before?

Yes, and recently. In April 2023, attackers began exploiting CVE-2023-27350, a critical bug that let unauthenticated attackers run code on PaperCut servers.

Microsoft tied some of that activity to the Clop ransomware crew, the same group behind the MOVEit mass-extortion campaign, and also saw the LockBit gang piling in. Iranian state-backed groups joined later. In May 2023, the US Cybersecurity and Infrastructure Security Agency and the FBI warned that the Bl00dy ransomware gang was using the same flaw to attack schools.

That pattern is why this new advisory matters. When PaperCut bleeds, ransomware crews tend to be first through the door.

Detail This incident (2025) 2023 incident
CVE ID Not yet assigned CVE-2023-27350
Affected products All versions of PaperCut NG and MF PaperCut NG and MF
Status at disclosure Active exploitation, emergency patch out Active exploitation, patch available
Known attackers Not disclosed Clop, LockBit, Bl00dy, Iranian state groups

For ordinary staff at organisations that use PaperCut for printing, there is nothing to do at your desk. Print jobs will keep working. The fix lives with your IT team, and the sooner they apply it, the smaller the window criminals have.

© 2026 Threat Vectr