PaperCut print servers under active attack via unpatched flaw
PaperCut says hackers are breaking into print management servers using a bug that affects every version of NG and MF. Emergency patches are out.

Key points
- PaperCut confirmed on Thursday that hackers are actively exploiting a previously unknown flaw in every version of its PaperCut NG and PaperCut MF print management software.
- The company has issued an emergency patch for customers whose PaperCut servers are reachable from the public internet.
- PaperCut has not said who is behind the attacks, what the attackers do once inside, or whether any data has been stolen.
- Administrators are told to lock the web interface down to trusted IP addresses and check server logs for specific error messages.
- The same product was hit hard in 2023, when the Clop and LockBit ransomware crews used a different PaperCut bug to break into corporate networks.
PaperCut, the Australian maker of print management software used by universities, hospitals and large offices, says criminals are actively breaking into its servers using a zero-day, meaning a software flaw the vendor did not know about until attacks started.
The company published an urgent advisory on Thursday saying its security team is "investigating active exploitation" and is "aware of confirmed customer incidents." It reproduced the bug using details supplied by a university customer that was attacked.
Every version of PaperCut NG and PaperCut MF is affected. The company has not published a CVE identifier, a CVSS score, or a technical description of the flaw yet. (That is unusual for a live exploitation advisory, and worth flagging.)
What should PaperCut customers do right now?
Install the emergency patch and get the web interface off the open internet. PaperCut has released a fix aimed specifically at customers whose Application Servers, the machine that runs the admin console, are reachable from anywhere on the internet.
If patching immediately is not possible, PaperCut wants administrators to use firewall rules or network access controls so that only trusted IP addresses can reach the web interface. That single change would take most exposed servers out of the line of fire.
The advisory also lists indicators of compromise, meaning signs that a server has already been broken into. Admins should look for:
- Suspicious activity coming from the legitimate
pc-app.exeprocess. server.logfiles that have been modified, deleted, or are missing entirely.- Two specific error strings in
server.log:ERROR No suitable driver found for jdbc:no:xandERROR DatabaseUtils - Database error looking up cardID: VALUES CAST.
PaperCut warns that a clean log does not mean a clean server. Attackers may be wiping traces.
Who is being targeted?
PaperCut has not named the attackers or their motive. The only detail confirmed so far, first reported by BleepingComputer, is that a university customer supplied the information that let PaperCut reproduce the bug. Whether the attackers are after ransomware access, stored print jobs, or something else is not yet known.
The product's install base is large. Universities, school districts, and healthcare providers are common PaperCut users, and those sectors have been hit repeatedly through this vendor before.
Has this happened to PaperCut before?
Yes, and recently. In April 2023, attackers began exploiting CVE-2023-27350, a critical bug that let unauthenticated attackers run code on PaperCut servers.
Microsoft tied some of that activity to the Clop ransomware crew, the same group behind the MOVEit mass-extortion campaign, and also saw the LockBit gang piling in. Iranian state-backed groups joined later. In May 2023, the US Cybersecurity and Infrastructure Security Agency and the FBI warned that the Bl00dy ransomware gang was using the same flaw to attack schools.
That pattern is why this new advisory matters. When PaperCut bleeds, ransomware crews tend to be first through the door.
| Detail | This incident (2025) | 2023 incident |
|---|---|---|
| CVE ID | Not yet assigned | CVE-2023-27350 |
| Affected products | All versions of PaperCut NG and MF | PaperCut NG and MF |
| Status at disclosure | Active exploitation, emergency patch out | Active exploitation, patch available |
| Known attackers | Not disclosed | Clop, LockBit, Bl00dy, Iranian state groups |
For ordinary staff at organisations that use PaperCut for printing, there is nothing to do at your desk. Print jobs will keep working. The fix lives with your IT team, and the sooner they apply it, the smaller the window criminals have.



